Impact
A use‑after‑free bug in Google Chrome’s PDF rendering engine allows an attacker to execute arbitrary code within the browser’s sandbox by loading a specially crafted HTML page that references a PDF. If the page is opened in a victim’s browser, the freed memory can be accessed and overwritten, enabling the attacker to run malicious code inside the confined environment of the browser sandbox.
Affected Systems
Google Chrome versions earlier than 153.0.8010.47 on any operating system are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. Its EPSS score is less than 1%, showing a low probability of exploitation in the current environment, and it is not listed in the CISA KEV catalog. The likely attack vector is a remote user opening a malicious HTML page that triggers the PDF rendering flaw, which then permits code execution inside the sandboxed browser process.
OpenCVE Enrichment