Impact
Google Chrome versions prior to 153.0.8010.36 contain a use‑after‑free flaw in the Passwords component. The defect allows a remote attacker to exploit social‑engineering techniques to trigger a UI interaction that can execute arbitrary code outside the browser sandbox. The vulnerability is a classic memory‑management error that compromises both confidentiality and integrity of the system with potential system‑wide impact.
Affected Systems
The flaw affects all installations of Google Chrome built before version 153.0.8010.36. Any user who has not upgraded past this release is potentially exposed.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploitation at the time of analysis. Chromium rates the issue as a medium severity bug, but the ability to deliver code outside the sandbox elevates the risk. Likely exploitation would require a user to interact with a crafted UI element, making social engineering a necessary precondition. The CVSS score of 9.6 indicates this vulnerability is critically severe.
OpenCVE Enrichment
Debian DLA
Debian DSA