Impact
The vulnerability is a use‑after‑free condition located in Chrome's authentication logic. An attacker can trigger it by delivering a crafted HTML page to a victim user. Once the bug is triggered, the attacker can execute code outside Chrome's sandbox, potentially compromising the CWE‑416.
Affected Systems
The flaw exists in Google Chrome versions older than 153. Users running any prior release are susceptible. Versions 153.0.8010.47 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. The EPSS score is below 1%, suggesting low current exploit prevalence, and the issue is not listed in the CISA KEV catalog. Nevertheless, an attacker can exploit the bug over the internet with a crafted page, gaining execution privileges on the victim's machine.
OpenCVE Enrichment