Impact
Google Chrome contains a use‑after‑free bug in the Receiver component that permits an attacker who can send specially crafted network traffic to execute arbitrary code outside the browser sandbox. The flaw results from failure to correctly manage memory deallocation, classified as CWE‑416. Successful exploitation would give the attacker unrestricted code execution on the victim’s system, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects all Chrome installations running any version prior to 153.0.8010.36 on desktop platforms. No specific operating system or hardware variant is mentioned; the impact applies to any system using the affected Chrome build as the web client.
Risk and Exploitability
The CVSS score of 8.3 indicates a high‑severity flaw, and the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based, with an attacker able to inject crafted packets to the Receiver component. The flaw allows remote code execution outside the sandbox, representing a significant risk if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA