Impact
Use after free in the Core component of Google Chrome before version 153.0.8010.36 allows a remote attacker, through social engineering, to craft a malicious extension that runs arbitrary code outside the browser sandbox. The flaw is a classic memory-safety issue (CWE‑416) that compromises confidentiality, integrity, and availability.
Affected Systems
Any user running Google Chrome on the stable channel older than version 153.0.8010.36, including desktop builds, is affected. The vulnerability resides in Chrome itself, and the fix exists in the latest stable release.
Risk and Exploitability
The vulnerability is classified as critical with a CVSS score of 9.6. Remote code execution is possible once a user installs the crafted extension, likely through a phishing or social‑engineering attack. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the flaw is not listed in CISA KEV. The high impact warrants prompt patching.
OpenCVE Enrichment
Debian DLA
Debian DSA