Impact
This vulnerability is a use–after–free bug in the DevTools code path of Google Chrome. A crafted HTML page that is loaded into the DevTools inspector can cause the browser to free shared memory and then dereference it again, giving the attacker the ability to execute arbitrary code outside the Chrome sandbox. The flaw corresponds to CWE‑416 and permits remote code execution, potentially allowing full compromise of the system where the browser is running if the sandbox is bypassed.
Affected Systems
The flaw affects Google Chrome browsers on all platforms for versions prior to 153.0.8010.36. The affected builds include the stable channel and developer releases that include the impacted DevTools engine. Users running earlier builds are vulnerable until they apply the patch delivered in the 153.0.8010.36 update, which removes the use‑after‑free in the DevTools module.
Risk and Exploitability
Chromium rates the issue as low severity, but the CVSS score of 9.6 indicates a critical impact. It has an EPSS score of 0.00354 (i.e., < 1%) and is not listed in KEV. Because the exploit requires a malicious HTML page to be opened in DevTools, a direct remote attack would need the user to launch DevTools or a remote debugging session with access to the page. It is inferred that the attack vector is limited to interactive or contextual attacks, which reduces the likelihood of widespread compromise. However, once triggered, the out‑of‑sandbox code execution gives the attacker full control over the host operating system. Updating to a fixed version removes the vulnerability and is the recommended course of action.
OpenCVE Enrichment
Debian DLA
Debian DSA