Impact
The reported flaw is a use‑after‑free bug in the Views component of Google Chrome prior to build 153.0.8010.36. When triggered by a local actor, the vulnerability allows execution of arbitrary code outside the browser sandbox. The issue maps to CWE‑416, indicating that freed memory was incorrectly accessed, leading to a critical integrity bypass.
Affected Systems
Affected systems are installations of Google Chrome running any version earlier than 153.0.8010.36. The problem is confined to the desktop browser; no server or mobile versions are mentioned. Users of the stack are expected to be running Windows, macOS, or Linux desktop editions of Chrome.
Risk and Exploitability
The vulnerability is categorized as high severity by Chromium, reflecting its potential for unrestricted code execution on the local machine. The exploit requires a local program to exploit the bug, so remote exploitation is not feasible without prior local access. The CVSS score is 8.1, and the EPSS score is less than 1%. The issue is not listed in CISA’s KEV catalog. The likely attack vector is a local attacker who has any form of local user or programmatic access, possibly via a malicious website or an installer. Given the high impact this flaw offers, users are strongly advised to update immediately.
OpenCVE Enrichment
Debian DLA
Debian DSA