Impact
The vulnerability is a Use‑After‑Free flaw (CWE‑416) in Google Chrome's WebPackaging component that allows a remote attacker, by serving a crafted HTML page, to execute arbitrary code outside the browser sandbox. Chromium reports the impact as a low‑severity issue, yet the nature of the flaw—memory corruption leading to potential code execution—makes it a serious threat if exploited.
Affected Systems
The flaw affects Google Chrome versions prior to 153.0.8010.36 running on desktop platforms. Users of any affected release are vulnerable; those on the mentioned or earlier versions require remediation.
Risk and Exploitability
An attacker would need to host or deliver the malicious HTML content to the victim’s browser, typically via a compromised website or social engineering. The CVSS score of 9.6 indicates extremely high severity, while the EPSS score of < 1% suggests a low probability of exploitation, and the lack of a CISA KEV listing means no widespread exploitation is known. Given that this is not a sandbox escape per se, but an RCE that bypasses browser isolation if achieved, the risk is elevated for users accessing untrusted content.
OpenCVE Enrichment
Debian DLA
Debian DSA