Impact
Race condition in the ReadAloud feature of Google Chrome before version 152.0.7977.65 allows an attacker who lures a user with a crafted HTML page to execute arbitrary code inside the browser sandbox. This flaw is classified as CWE-362, indicating that concurrent execution of threads leads to inconsistent state, allowing sandboxed code execution.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. Users running the Stable channel build before this version remain vulnerable.
Risk and Exploitability
The CVSS score of 8.3 reflects high severity; the EPSS score is < 1%, indicating low expected exploitation frequency, and the vulnerability is not listed in the CISA KEV catalog. The attack vector relies on user interaction with a malicious web page, exploiting a race condition in ReadAloud to trigger code execution within the sandbox. The resulting execution is confined to the sandboxed environment and does not escape the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA