AI analysis
A use-after-free flaw (CWE-416) in the Views component of Google Chrome, fixed in version 154.0.8037.92, allows a remote attacker to corrupt memory and execute arbitrary code outside the browser sandbox. Triggering it requires social engineering — typically a phishing message or link that lures the victim to open a crafted HTML page — but no authentication or privileges beyond that user interaction. Because successful exploitation escapes the sandbox, the attacker gains code execution in the context of the underlying operating system user, giving full impact on confidentiality, integrity, and availability (CVSS 3.1: 9.6; Chromium severity: High). Anyone running Google Chrome versions prior to 154.0.8037.92 is affected, and Chromium-based browsers typically inherit engine flaws of this kind until their vendors rebase. As of this analysis, the issue is not in CISA's KEV catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been confirmed.
What to do: Update Google Chrome to version 154.0.8037.92 or later immediately (Chrome > Settings > About Chrome forces the update), and enterprise admins should confirm the rollout via update policies, including any Extended Stable channel lag. Users of Chromium-based browsers such as Edge, Brave, Opera, and Vivaldi should apply those vendors' latest updates, since they inherit Chromium engine fixes on their own release schedules. Since exploitation hinges on a victim clicking a crafted link, reinforce phishing awareness, but patching is the primary and decisive mitigation.
Affected
| Google Chrome | prior to 154.0.8037.92 |
Estimated exposure
mass≈3 billion Chrome users globally (~65% browser market share); the unpatched subset plausibly numbers in the hundreds of millions — Estimated from Chrome's dominant global browser market share (roughly 60-65% across desktop and mobile per public trackers) applied to the total internet-using population, discounted by how quickly Chrome's auto-update propagates the fix.