Impact
A use‑after‑free flaw exists in the WebGL implementation of Google Chrome that enables a remote attacker, who controls a crafted HTML page, to escape the browser sandbox and execute arbitrary code. The vulnerability is catalogued as CWE‑416 and, if exploited, grants the attacker the privileges of the Chrome process, allowing full system compromise, including reading and modifying files, injecting malware, or pursuing lateral movement on the affected machine.
Affected Systems
Users running Google Chrome versions earlier than 153.0.8010.36 are affected. The issue appears to be limited to the stable channel version of the browser and targets only the WebGL subsystem.
Risk and Exploitability
Chromium rates the flaw as Critical; the CVSS score is 9.6, the EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, as an adversary can host a malicious web page that triggers the use‑after‑free in a victim’s browser, leading to execution outside the normal sandbox. The minimal EPSS score does not diminish the threat posed by a flaw that allows arbitrary code execution from untrusted web content.
OpenCVE Enrichment
Debian DLA
Debian DSA