Impact
A use‑after‑free vulnerability exists within the Views component of Google Chrome prior to version 153.0.8010.36. The flaw permits a local attacker to execute arbitrary code with privileges higher than those of the user’s sandbox when interacting with the user interface. Because the attacker must be able to manipulate the UI, the attack is confined to a local context, but the impact includes total compromise of the machine if the exploitation succeeds.
Affected Systems
All installations of Google Chrome running any version before 153.0.8010.36 are affected. The vulnerability is present in the stable channel and applies to desktop deployments of Chrome.
Risk and Exploitability
The CVE has a CVSS score of 8.6, indicating high severity. The EPSS score is below 1%, implying a low, yet non‑zero likelihood of exploitation. The issue is not listed in CISA’s KEV catalog. The vulnerability allows local privilege escalation and arbitrary code execution. Exploitation requires local access and the ability to trigger the vulnerable UI path, so it is less likely to be remotely leveraged but remains a significant risk on shared or multi‑user systems.
OpenCVE Enrichment
Debian DLA
Debian DSA