Impact
The vulnerability is a use-after-free flaw in the WebAppInstalls component of Google Chrome. A crafted HTML page can trigger the bug, allowing an attacker to execute arbitrary code with the privileges of the browser process and escape the sandbox, resulting in full system compromise.
Affected Systems
Google Chrome versions earlier than 153.0.8010.47 are affected. The flaw exists in the WebAppInstalls subsystem and applies to any Chrome installation that permits web app installation pages.
Risk and Exploitability
The severity is high with a CVSS score of 9.6, but the EPSS score of less than 1% indicates the current probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. A likely attack vector is a maliciously crafted web page that a user visits, which causes the use-after-free bug to run code outside the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA