Impact
A use‑after‑free flaw in Chrome’s PDFium rendering engine allows a remote attacker to execute arbitrary code inside the browser sandbox. The vulnerability is classified as CWE‑416. The impact is that the attacker can run code with the privileges of the Chrome process, potentially enabling further system compromise depending on the underlying operating system. The CVSS score of 8.8 reflects a high severity for this type of memory misuse.
Affected Systems
All desktop installations of Google Chrome running a version older than 153.0.8010.52 are vulnerable. Versions 153.0.8010.52 and newer incorporate the fix, but any machine that has not yet updated remains exposed.
Risk and Exploitability
The CVSS score of 8.8 indicates a significant risk of exploitation. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present. The vulnerability is not listed in CISA KEV. The likely attack vector is inferred to be a remote attacker delivering a malicious web page that includes specially crafted HTML content, based on the description that the flaw can be triggered via a crafted HTML page. Prompt patching is therefore essential to prevent potential remote code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA