Impact
The vulnerability is a use‑after‑free condition in Chrome’s input handling that can be triggered by a crafted HTML page. When the condition is satisfied, a remote attacker can potentially execute arbitrary code outside the browser sandbox, leading to compromise of confidentiality, integrity, and availability of the host system. The official severity rating is medium, and the CVE is assigned a CVSS score of 8.8, indicating a high‑risk flaw.
Affected Systems
Google Chrome versions prior to 153.0.8010.47 are affected. The issue applies to all platforms where this Chrome build runs, as the vulnerability resides in a core input component used across browser instances.
Risk and Exploitability
Although the EPSS score is below 1%, the high CVSS score demonstrates significant potential impact. The flaw is not listed in CISA’s KEV catalog, so no known widespread exploitation is documented. The most likely attack vector is via a maliciously crafted HTML document loaded in the browser, potentially delivered through a phishing link or embedded in a website. Successful exploitation would allow code to run with desktop privileges, bypassing the typical sandboxing model.
OpenCVE Enrichment