Impact
The vulnerability is a Use After Free (CWE‑416) flaw in Chrome’s core code that allows an attacker to craft a freed memory reference that is later accessed, enabling code execution beyond the intended security boundaries.
Affected Systems
All users running Google Chrome prior to version 153.0.8010.47 are potentially affected. The CVE description does not restrict the impact to any specific platform, so desktop, embedded, or mobile versions of Chrome could be vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 9.6 and has an EPSS score of less than 1%. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker only needs to supply a malicious HTML page, so the attack vector is remote and exploits the browser’s privileges, and the attacker can achieve full code execution on the local system, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment
Debian DLA
Debian DSA