Impact
This vulnerability is a use‑after‑free flaw in the Aura component of Google Chrome. The flaw allows a remote attacker to cause the browser to execute code outside of its sandbox when a specially crafted HTML page is loaded. The weakness is categorized as CWE‑416 and could potentially lead to full remote code execution on the victim’s machine.
Affected Systems
All users running Google Chrome versions earlier than 153.0.8010.36 are affected. The issue exists in the stable channel updates for desktop Chrome and is not limited to a particular operating system or device type.
Risk and Exploitability
The Chromium security team rates the issue with a CVSS score of 9.6, indicating a high severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation in real‑world attacks, and the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known widespread exploitation. The attack vector is inferred to be remote via the delivery of a malicious HTML page, which can be served from a web server or injected through other user‑controlled input. Given the nature of the flaw, an attacker who forces the browser to load the crafted page can potentially take control of the victim’s system.
OpenCVE Enrichment
Debian DLA
Debian DSA