Impact
Google Chrome contains a use‑after‑free bug in the Web Authentication implementation that allows an attacker to run arbitrary code outside the browser sandbox. A malicious web page that the user visits can trigger the flaw, resulting in a remote code execution that compromises the entire system. The bug is classified as CWE‑416 and is rated with high severity by Chromium (CVSS 9.6).
Affected Systems
The vulnerability exists in all Chrome releases before 153.0.8010.36. Systems running that older version are exposed, regardless of operating system or device type.
Risk and Exploitability
The CVE has not been recorded in the CISA KEV list and the EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. Nevertheless, remote execution via a crafted HTML page suggests the attack vector is a web‑based threat that could be delivered through phishing or compromised sites. The high severity rating combined with the confirmed ability to escape the browser sandbox makes this a critical security risk.
OpenCVE Enrichment
Debian DLA
Debian DSA