Impact
A use‑after‑free flaw exists in the Workers implementation of Google Chrome versions before 153.0.8010.47. The flaw can be triggered by a crafted HTML page, allowing an attacker to run arbitrary code outside the browser sandbox. This vulnerability is classified as a critical security issue, providing the attacker with full control of the system on which Chrome is running.
Affected Systems
Google Chrome users affected by this vulnerability are those running any build prior to version 153.0.8010.47, including all 152.x releases and earlier. Chrome versions 153.0.8010.47 and later contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 9.6, indicating a high severity for remote exploitation. The EPSS score is below 1 %, which suggests that, while the attack is feasible, it has not yet been widely observed in the wild and is not listed in CISA’s KEV catalogue. The attack vector is inferred to be a malicious web page that the victim opens in Chrome, taking advantage of the susceptible Workers implementation to achieve code execution beyond the usual sandbox constraints.
OpenCVE Enrichment