Impact
The vulnerability is a double free in PDFium, the PDF rendering engine used by Google Chrome on Windows. The double free can be triggered by a specially crafted PDF file and can lead to arbitrary code execution inside Chrome’s sandbox process, which may allow the attacker to escape the limited sandbox and compromise the host system.
Affected Systems
Google Chrome running on Windows is affected. Any Windows build of Chrome older than version 153.0.8010.36 contains the flaw; versions 153.0.8010.36 and newer have the fix.
Risk and Exploitability
Chromium labels the issue as high severity, with a CVSS score of 8.8. The exploit is achieved remotely via a malicious PDF, so an attacker may embed the exploit in an email attachment or a malicious website. The double free leads to code execution within the sandboxed renderer; although the sandbox limits the damage, escape remains possible. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, so public exploitation likelihood is uncertain, but the potential impact justifies urgent remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA