Impact
A race condition in the handling of file downloads in Google Chrome on macOS allows a compromised renderer process to potentially escape the browser sandbox by manipulating a crafted HTML page. The vulnerability stems from improper synchronization during download operations, enabling the attacker to trigger ambiguous state changes between checking and using download resources. If exploited, the attacker could gain read or write access to protected filesystem locations or execute arbitrary code beyond the browser sandbox, compromising the confidentiality, integrity, or availability of the host system.
Affected Systems
All macOS users running Google Chrome versions earlier than 151.0.7922.72 are susceptible. The vulnerability specifically targets the renderer subprocess, which is already isolated but may be compromised through other attack vectors. No other operating systems or product variants are listed as affected.
Risk and Exploitability
The CVSS score of 9.6 reflects high severity, and the EPSS score is below 1% indicating a low current likelihood of exploitation. The flaw is not yet listed in CISA KEV, nor is there an active exploit reported in the public domain. The attack vector is inferred to require remote control over the renderer process; a remote attacker who has already compromised the renderer could trigger the race condition by serving a malicious HTML page. Given the high impact and the low probability of exploitation, organizations with high exposure should monitor for local compromise of Chrome’s renderer processes and prioritize patching.
OpenCVE Enrichment
Debian DLA
Debian DSA