Impact
The vulnerability is a use‑after‑free flaw in the DigitalCredentials component of Google Chrome that allows an attacker to run arbitrary code outside the browser sandbox. When a crafted HTML page containing a malicious DigitalCredentials request is processed, the freed memory can be dereferenced, leading to execution of attacker‑supplied code. The flaw is categorized as CWE‑416 and also involves CWE‑825, indicating improper privilege management that allows the code to escape sandbox restrictions. This can result in full system compromise, loss of confidentiality and integrity for any user that’s tricked into opening the page.
Affected Systems
All releases of Google Chrome prior to version 153.0.8010.47 are affected. The vulnerability exists across all operating systems that support the Chromium engine, and it is specifically listed for Google:Chrome in the CNA product list.
Risk and Exploitability
The CVSS score of 9.6 marks this as a critical vulnerability. However, the EPSS score of <1% indicates that, in the wild, exploitation attempts are expected to be very rare. The vulnerability is not listed in CISA’s KEV catalog, and it requires a social‑engineering attack vector that involves a user visiting a maliciously crafted HTML page. Once executed, the attacker can run code with operating‑system privileges, bypassing browser isolation mechanisms.
OpenCVE Enrichment
Debian DLA
Debian DSA