Impact
The vulnerability is a use‑after‑free flaw in the Skia graphics library used by Google Chrome. An attacker can deliver a specially crafted HTML page that causes the browser to free an object and then allocate it for another purpose, enabling execution of arbitrary code inside the sandboxed renderer process. This flaw allows the attacker to take control of the rendering process, potentially compromising the browser’s integrity and confidentiality of data processed within that process.
Affected Systems
Google Chrome versions earlier than 152.0.7977.82 are affected. Users running the stable channel of Chrome prior to this build are at risk.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity. The vulnerability can be triggered remotely from a web page visited in the browser; thus the likely attack vector is a malicious website. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog, but the high severity and remote nature suggest a significant exploitation risk in the absence of a patch.
OpenCVE Enrichment
Debian DLA
Debian DSA