Impact
An attacker who has already compromised the renderer process can load a crafted HTML page that triggers a use‑after‑free in Chrome’s printing subsystem. The flaw allows arbitrary code execution outside the browser sandbox, giving the attacker full system privileges. This high‑severity bug could lead to complete compromise of the user’s machine.
Affected Systems
Google Chrome browsers running any version prior to 153.0.8010.36 are affected. The vulnerability is limited to releases bundled with the previous printing implementation.
Risk and Exploitability
Because a renderer must already be compromised to trigger the flaw, the attack requires local or remote execution of malicious content that gains renderer privileges. The CVSS score of 8.3 indicates high severity, and the ability to escape the sandbox suggests a significant risk if the vulnerability is reached. The EPSS score is low (<1%) and the absence from the KEV catalog indicates that public exploit data is not yet available. An exploit would enable execution of code with the same privileges as the user, potentially persisting through sandbox boundaries.
OpenCVE Enrichment
Debian DLA
Debian DSA