Impact
Chrome on Windows before version 153.0.8010.36 contains a use‑after‑free vulnerability in the ANGLE graphics library. This flaw allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that can execute arbitrary code outside the sandbox. The attack compromises confidentiality, integrity, and availability by enabling code execution under the user’s privileges.
Affected Systems
The affected system is Google Chrome running on Windows machines. Versions earlier than 153.0.8010.36 are impacted; the vulnerability exists in the renderer component when ANGLE is used.
Risk and Exploitability
The CVSS severity is high with a score of 8.3, and the EPSS score is <1%, indicating a very low exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers must first gain the ability to execute code within the renderer process, which is a privileged but non‑elevated context; from there, they can use the use‑after‑free to run code outside the sandbox. The window of opportunity exists while the vulnerable processor execute path is active and the browser is loading a crafted HTML page.
OpenCVE Enrichment
Debian DLA
Debian DSA