Impact
The flaw is an improper initialization in the Views component of Google Chrome running on Windows. If an attacker can gain control of the renderer process and trick a user into loading a crafted HTML page, the attacker may execute arbitrary code outside the browser’s sandbox. The vulnerability is rated Chromium severity Medium, indicating that successful exploitation can lead to full system compromise.
Affected Systems
Windows users running Google Chrome versions earlier than 153.0.8010.36 are affected. The patch that fixes this issue is shipped in the stable channel update released after that version.
Risk and Exploitability
EPSS score of 0.00279 indicates a very low probability that this vulnerability has been exploited in the wild. The issue is not listed in the CISA KEV catalog, so no baseline exploitation metrics exist. The CVSS score of 8.3 indicates high severity, meaning that a successful exploit could provide an attacker with full code execution on the victim’s machine. The likely attack vector involves a phishing or social‑engineering attempt that convinces a user to open a malicious web page that triggers the malformed View initialization, forcing the renderer to execute code outside its sandbox. Because the exploit requires an already compromised renderer, the opportunity for impact is limited to environments where such control is feasible, resulting in a moderate overall risk pending successful exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA