Impact
The vulnerability is a use‑after‑free in Google Chrome’s browser component on Windows that allows a remote attacker to execute arbitrary code outside the sandbox. The flaw originates from memory management issues triggered by a malicious HTML page and can be exploited by social engineering. If successful, the attacker can gain the same privileges as the Chrome process, potentially compromising the host system.
Affected Systems
Affected are Windows installations of Google Chrome with versions earlier than 153.0.8010.36. All users running these versions are vulnerable until they upgrade to the patched release or later.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. The high CVSS score of 9.6 indicates a severe impact if exploited. The Chromium severity is Medium, but the exploit could be achieved remotely via a crafted web page that a user opens. The lack of a low EPSS score suggests current exploitation may be rare, yet the impact is high. The flaw is a typical Use‑after‑Free (CWE‑416) and could be leveraged when the attacker succeeds in exploiting the vulnerability through a social‑engineering attack vector linked to browsing a malicious page.
OpenCVE Enrichment
Debian DLA
Debian DSA