Impact
A use‑after‑free flaw in Google Chrome’s extension handling allows a remote attacker to execute code with the privileges of the Chrome process, potentially compromising the underlying operating system. The flaw arises when an extension frees a memory object and later references it again, leading to arbitrary code execution outside the sandbox. It is a CWE-416 use‑after‑free vulnerability.
Affected Systems
Google Chrome installations prior to version 153.0.8010.52 on all supported operating systems are affected. The vulnerability is present in every build of Chrome in which the specific extension handling code existed, regardless of platform.
Risk and Exploitability
The CVSS score of 9.6 rates this vulnerability as critical. The EPSS score of less than 1% indicates a very low but nonzero probability of exploitation. It is not currently listed in the CISA KEV catalog. The likely attack vector involves a malicious or compromised Chrome extension that the user installs or activates; the attacker must persuade the user to run the extension for exploitation to succeed.
OpenCVE Enrichment
Debian DLA
Debian DSA