Impact
Google Chrome versions prior to 153.0.8010.47 contain a use‑after‑free flaw in the Input component that enables a remote attacker who has compromised the renderer process to execute arbitrary code outside of the sandbox. The defect is a classic use‑after‑free error (CWE‑416) that can result in arbitrary code execution (CWE‑825). The vulnerability is rated high severity, indicating serious potential damage to confidentiality, integrity, and availability for affected users.
Affected Systems
The flaw affects all installations of Google Chrome (the Chromium browser) that are running a version earlier than 153.0.8010.47, regardless of operating system. The patch was released in the stable channel update for desktop browsers as referenced by the official Chrome release page.
Risk and Exploitability
The CVSS score for the issue is 8.3, confirming high impact. An EPSS score of less than 1% reflects a very low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, relying on a crafted HTML page that a user loads, which then triggers the already compromised process. No known public exploit exists, so the exploitation likelihood remains minimal but the potential impact is severe if the flaw is triggered.
OpenCVE Enrichment