Impact
The vulnerability is a use‑after‑free in the Chrome DevTools component that allows a local attacker to run arbitrary code outside the browser sandbox when a local program interacts with DevTools. The flaw is related to missing memory safety checks and is categorized as CWE‑416. As a result, the attacker can compromise the host system with the privileges of the user running the affected Chrome installation.
Affected Systems
Google Chrome desktop versions released before 153.0.8010.36 are affected. The vendor has addressed the issue in the 153.0.8010.36 release and later builds.
Risk and Exploitability
The CKV exploit is local – it requires the attacker to run a program on the target machine that can open or establish a connection to DevTools. The CVSS score is 8.1. The EPSS score indicates that the probability of exploitation is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Chromium rates the issue as Medium severity. Because the attack vector is purely local, the practical risk depends on the local environment and user privileges, but once exploited, the attacker can execute any code with user rights.
OpenCVE Enrichment
Debian DLA
Debian DSA