Impact
A type confusion bug in Chrome’s Rust components on Windows allows a remote attacker to send a specially crafted HTML page that can bypass the sandbox and execute code with elevated privileges, matching the CWE‑843 classification of unsafe type conversion.
Affected Systems
The flaw affects every user of Google Chrome on Windows running a version prior to 153.0.8010.36. Versions earlier than this release are vulnerable until an update containing the fix is installed.
Risk and Exploitability
The CVSS score of 9.6 reflects the high potential impact of this flaw, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: an adversary must host or deliver a malicious HTML page that the vulnerable browser will render. No publicly available exploit is known, so current risk is moderate, but the severity warrants immediate action to prevent a potential catastrophic compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA