Impact
The vulnerability is a Use After Free (CWE‑416) flaw in Chrome’s core code that allows an attacker to crafted a freed memory reference that is later accessed, enabling code execution beyond the intended security boundaries.
Affected Systems
All users running Google Chrome prior to version 153.0.8010.47 are affected. The issue is specific to the Chrome browser on desktop platforms and does not affect embedded or mobile versions reported in the CVE description.
Risk and Exploitability
The vulnerability scores a CVSS of 9.6 and has an EPSS score of less than 1%. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker only needs to supply a malicious HTML page, so the attack vector is remote and exploits the browser’s privileges, and the attacker can achieve full code execution on the local system, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment