Impact
This vulnerability is a use‑after‑free bug in the Cast component of Google Chrome that can be triggered by crafted network traffic. The flaw allows an adjacent attacker to potentially execute arbitrary code outside of the browser sandbox, giving them the ability to compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
The bug affects all versions of Google Chrome prior to 153.0.8010.36. Users running older releases are at risk until they upgrade to the patched version.
Risk and Exploitability
Chromium labels the fix as critical, and the CVSS score is 8.3 with an EPSS score of < 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to deliver crafted network traffic to the vulnerable Cast service. While the EPSS score indicates a low exploitation probability, the critical severity suggests that the bug is worth treating with high urgency for patching.
OpenCVE Enrichment
Debian DLA
Debian DSA