Impact
A use‑after‑free flaw in Chrome’s V8 JavaScript engine is triggered by a specially crafted HTML page that a remote attacker can deliver. When the vulnerable function frees an object that is still in use, the attacker’s injected code can execute inside the browser’s sandbox, allowing arbitrary code execution. The flaw is rated high severity by Chromium security and is classified as CWE‑416, a classic memory corruption weakness, and CWE‑825, which involves improper handling of freed memory and other memory safety issues.
Affected Systems
Google Chrome versions preceding 153.0.8010.47 are vulnerable. This includes all stable channel releases older than that version. Any system with an unpatched installation of Chrome that can load an arbitrary web page is at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates that a successful exploit can have a high impact on confidentiality, integrity, and availability of the affected host. The EPSS score of less than 1 % suggests that, while the vulnerability is technically exploitable, the probability of real‑world exploitation is currently low. The issue is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote web page that the victim visits, which then triggers the use‑after‑free inside V8 to run the attacker’s code within the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA