Impact
Use after free vulnerability in the WebAppInstalls component of Google Chrome allows a remote attacker to in the browser, can cause the browser to execute arbitrary code outside the sandbox. The flaw is a classic use-after-free bug (CWE-416) that bypasses the browser's process isolation, enabling arbitrary code execution and full compromise of the host system.
Affected Systems
Google Chrome versions older than 153.0.8010.47 are affected. The vulnerability exists in the WebAppInstalls subsystem and impacts any installation of Chrome that allows Web App installation pages.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, indicating a high severity for remote code execution. The EPSS score is less than 1%, reflecting a low probability of exploitation at present. It is not listed in the CISA KEV catalog. The likely attack vector involves a maliciously crafted web page that a user visits, triggering the use-after-free bug and allowing an attacker to run code with the privileges of the browser process.
OpenCVE Enrichment