Impact
The flaw is a use‑after‑free in Chrome’s Internals module that, if triggered, can corrupt memory and lead to arbitrary code execution outside the browser sandbox. The Vulnerability description confirms that a crafted HTML page can potentially cause the browser to run code with the privileges of the user’s process, thereby offering the attacker a full compromise of the victim system.
Affected Systems
The advisory lists Google Chrome versions prior to 153.0.8010.47 as vulnerable. The description does not specify operating systems, but Chrome typically runs on Windows, macOS, and Linux, so the risk applies to all those platforms. This is an inference based on the product’s standard cross‑platform distribution.
Risk and Exploitability
The CVSS base score of 8.8 reflects high severity, and the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation currently. The vulnerability is not in the CISA KEV catalog. Attackers can exploit the flaw by serving a malicious web page to a user; upon loading the page, the use‑after‑free path is exercised, allowing the attacker to escape the sandbox and execute code on the victim’s machine.
OpenCVE Enrichment
Debian DLA
Debian DSA