Impact
Google Chrome contains a use‑after‑free flaw in its DOM processing, allowing an attacker who supplies a specially crafted HTML page to run arbitrary code inside the browser’s sandbox. The memory corruption error (CWE‑416) and improvement memory handling flaw (CWE‑825) result in code execution within the restricted environment of the sandboxed process, potentially compromising data accessed by the browser and any integrated extensions.
Affected Systems
All users operating Google Chrome versions earlier than 153.0.8010.47 are affected; the payload does not specify the operating system, so the impact may apply to any platform where Chrome runs.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, yet the EPSS score of less than 1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attack requires a malicious HTML page that a user opens; no remote network attack vector is necessary. Exploitation can only occur within the sandboxed process, limiting the scope to the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA