Impact
The vulnerability is a use-after-free flaw in the Metrics component of Google Chrome, classified as CWE-416. It allows a remote attacker to craft network traffic that triggers a use-after-free condition, enabling the execution of arbitrary code outside the browser sandbox. The impact is the compromise of the host system’s confidentiality, integrity, and availability, as the attacker can run code with kernel or system-level privileges if exploitation succeeds.
Affected Systems
Google Chrome version 154.0.8037.57 and earlier across all supported operating systems. The flaw affects any machine running those versions of Chrome and listening for external network traffic that can be crafted to target the vulnerable component.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at the time of this analysis. The likely attack vector is a remote attacker sending specially crafted traffic to a victim’s Chrome instance, potentially leveraging the browser’s ability to request network resources, such as HTTPS or HTTP requests, or WebSocket connections. While the precise exploitation conditions are not fully disclosed, the description indicates that arbitrary code execution outside the sandbox is possible.
OpenCVE Enrichment
Debian DSA