AI analysis
A use-after-free flaw (CWE-416) in Google Chrome's FullScreen component, in versions prior to 154.0.8037.92, frees memory that the browser subsequently reuses while handling the fullscreen API, allowing a remote attacker to corrupt heap memory through a crafted HTML page. Because the impact escapes Chrome's sandbox (CVSS scope: changed, 9.6), successful exploitation gives the attacker arbitrary code execution with the privileges of the logged-in user rather than the confined renderer process. The attack requires no authentication or privileges and only modest user interaction — typically luring a victim to a malicious or compromised website that triggers the buggy fullscreen code path. All users running an unpatched build are exposed, and other Chromium-based browsers that incorporate the same FullScreen code may inherit the flaw until their vendors ship updated builds. Google rates the issue High severity; no public proof of concept exists and it is not on CISA's KEV list, so no exploitation in the wild is currently known.
What to do: Update to Chrome 154.0.8037.92 or later immediately — users can confirm their build at chrome://settings/help, and enterprises should force the rollout via Chrome Browser Cloud Management or update policy. Organizations running Chromium-derived browsers (Edge, Brave, Opera, Vivaldi, embedded Chromium runtimes) should apply vendor updates as they become available, since they can inherit the vulnerable FullScreen code. Since exploitation only requires a victim to visit a hostile page, treat unexpected fullscreen requests from unfamiliar sites as suspicious and report them to security teams.
Affected
| Google Chrome | < 154.0.8037.92 |
Estimated exposure
mass≈2–3 billion users/installations (Chrome holds roughly 60–65% of global browser market share across desktop and mobile) — Estimated from Chrome's dominant global browser market share and multi-billion-install base; the practically exposed population shrinks rapidly as Chrome's auto-update mechanism pushes the patched 154.0.8037.92 build.