Impact
The vulnerability is a use‑after‑free condition in Chrome’s input handling module that can be triggered by a carefully crafted HTML page. If successfully triggered, it allows a remote attacker to execute arbitrary code outside the browser sandbox, potentially compromising the confidentiality, integrity, and availability of the host system. The weakness is classified under CWE‑416 and CWE‑825, and the CVSS score of 8.8 indicates a high‑risk impact.
Affected Systems
All users running Google Chrome versions prior to 153.0.8010.47 on any platform are affected because the flaw resides in a core input component used by every instance of the browser.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation is known. Nevertheless, the high CVSS score indicates significant potential impact. Based on the description, the likely attack vector is a maliciously crafted HTML document displayed in the browser, which a remote attacker could host or embed in a phishing link to trigger the use‑after‑free. Successful exploitation would elevate code execution outside the sandbox with desktop‑level privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA