Impact
A use‑after‑free flaw in Chrome’s iOS sharing component lets a remote attacker send crafted network traffic to trigger a memory error that can execute arbitrary code outside the browser sandbox. The vulnerability is classified as Medium severity by Chromium and meets CWE‑416. Successful exploitation would grant code‑execution privileges, potentially allowing full control over the device.
Affected Systems
Google Chrome for iOS versions earlier than 153.0.8010.36 on the stable channel are affected. The issue is limited to the mobile browser's sharing component.
Risk and Exploitability
The CVSS score is 9.6, indicating a critical vulnerability. The EPSS score is < 1%, suggesting a very low exploitation probability, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker delivering malicious content that triggers the failure, requiring no authentication and relying on Chrome’s network subsystem. Given the high severity and the minimal exploitation probability, the risk is still significant until the patch is deployed.
OpenCVE Enrichment
Debian DLA
Debian DSA