Impact
Use after free bug in Chrome's Platform component before version 153.0.8010.36 allows an attacker to run arbitrary code inside the sandbox via a crafted HTML page. The flaw is a classic use‑after‑free (CWE-416) and improper access to freed memory (CWE-825). Based on the description, it is inferred that the flaw could escape the sandbox and compromise the host. This vulnerability permits a remote attacker to tamper with local data, take over the browser process, and gain code execution on the user’s system.
Affected Systems
The issue affects Google Chrome browsers running versions earlier than 153.0.8010.36. Systems with a Chrome installation at or below that version are vulnerable. The vulnerability is confined to the Chrome application itself and does not involve the underlying operating system.
Risk and Exploitability
This vulnerability has a CVSS score of 8.8, indicating high severity, and is tied to a remote attacker delivering a malicious web page. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation, and the flaw is not listed in CISA’S KEV catalog. Exploitation requires the victim to visit a crafted page; a successful exploit would grant code execution within the Chrome sandbox, potentially escalating to the host if the sandbox is bypassed. Based on the description, it is inferred that risk is high for users who browse untrusted content.
OpenCVE Enrichment
Debian DLA
Debian DSA