Impact
A use‑after‑free bug (CWE‑416) in the V8 JavaScript engine of Google Chrome versions before 153.0.8010.36 allows an attacker to corrupt memory that has already been freed. An attacker who can run malicious extension code gains the ability to execute arbitrary code inside the limited privileges of the Chrome extension sandbox, which can then be leveraged to compromise the host system.
Affected Systems
All installations of Google Chrome that ship with a stable release channel at or before version 153.0.8010.36 on Windows, macOS, or Linux are affected. The flaw specifically targets the V8 engine used to execute extensions and webpages.
Risk and Exploitability
The exploit requires an attacker to convince a user to install a crafted Chrome extension, so the primary attack vector is user interaction through social engineering; this is inferred from the description. EPSS < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. Despite the high CVSS score of 8.8, the risk to environments that restrict extension installation remains moderate unless the extension ecosystem is widely open.
OpenCVE Enrichment
Debian DLA
Debian DSA