Impact
A use‑after‑free flaw in the DevTools component of Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. The vulnerability is triggered when a victim opens a malicious HTML document that exploits the freed memory in DevTools, enabling a local code execution path even though the attacker does not gain privileges outside the browser sandbox. The described exploit can be leveraged by social engineering techniques to trick users into loading the malicious page.
Affected Systems
Google Chrome is affected. Versions prior to 153.0.8010.36 are vulnerable. No further version details were supplied.
Risk and Exploitability
The CVSS score is 8.8 and the EPSS score is <1%, but Chromium rates the issue as low severity. Exploitation requires a victim to open a crafted HTML page and run DevTools, so the attack vector is remote web content combined with user interaction. The lack of a KEV listing suggests no known widespread exploitation at this time. Nevertheless, because the flaw permits remote code execution, it poses an immediate risk to any user of an affected Chrome build.
OpenCVE Enrichment
Debian DLA
Debian DSA