Impact
A race condition was discovered in the Enterprise version of Google Chrome running on Windows prior to 152.0.7977.65. Adversaries can send specially crafted network traffic to the vulnerable process, causing the race to resolve in a manner that allows the execution of arbitrary code outside of Chrome’s built‑in sandbox. The problem is classified as low severity but it grants the attacker the potential to elevate privileges on the affected machine.
Affected Systems
All Windows installations of Google Chrome that are below version 152.0.7977.65, including the Enterprise builds. These installations are susceptible to the race condition in the network handling code.
Risk and Exploitability
The CVSS assessment indicates a high severity rating (score 7.5) and the EPSS score is <1%, while the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local or adjacent, requiring the attacker to be in the same network segment or otherwise able to inject traffic to the browser process. Once the race condition is triggered, the attacker can bypass the sandbox and run code with the privileges of the Chrome user, potentially compromising the host or accessing confidential data.
OpenCVE Enrichment
Debian DLA
Debian DSA