Impact
A use‑after‑free flaw exists in the V8 JavaScript engine of Google Chrome prior to version 153.0.8010.36. This vulnerability allows a remote attacker to execute arbitrary code inside Chrome’s sandbox by loading a specially crafted HTML page. It is classified as a high‑severity memory corruption issue and is a classic example of a use‑after‑free condition leading to code execution.
Affected Systems
The issue affects all users running Google Chrome versions older than 153.0.8010.36; any system with this build exposed to web content is potentially vulnerable.
Risk and Exploitability
The vulnerability is a remote code execution flaw that permits a remote attacker to execute arbitrary code inside Chrome’s sandbox by loading a crafted HTML page. The exploit requires only that the victim open the malicious page; no other privileged actions are documented. The CVSS score of 8.8 indicates a high severity, and the EPSS score of <1% shows a very low exploitation probability. The issue is not listed in the CISA KEV catalog, and no publicly available exploit code is referenced in the CVE description.
OpenCVE Enrichment
Debian DLA
Debian DSA