Impact
A use‑after‑free vulnerability in the V8 engine allows an attacker who can serve a crafted HTML page to execute arbitrary code while the browser is running. Based on the description, it is inferred that the attacker can run malicious code with the privileges of the sandboxed process, which may bypass certain browser mitigation layers and could further exploit the operating system.
Affected Systems
Google Chrome users running versions of the stable channel prior to 153.0.8010.36 are affected. The issue was identified in the V8 engine component of the Chrome browser, which is distributed with all Chrome installations.
Risk and Exploitability
Based on the description, it is inferred that the likelihood of exploitation depends on the existence of phishing or drive‑by sites that can host such content. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog; based on this information, it is inferred that widespread exploitation has not yet been observed. Nonetheless, the CVSS score of 8.8 indicates a High severity level, and the flaw can be leveraged for remote code execution. The attack vector is inferred to be remote via a malicious web page delivered over the internet.
OpenCVE Enrichment
Debian DLA
Debian DSA