Impact
A race condition in the Chrome extensions subsystem allowed a remote attacker to bypass system access restrictions by installing a specially crafted extension. The flaw permits the attacker to gain privileged access to resources normally protected by the system's sandbox, potentially exposing sensitive data or executing privileged code. This weakness corresponds to CWE‑367, indicating a timing bug that disrupts proper access control enforcement.
Affected Systems
Google Chrome browsers running versions older than 152.0.7977.65 are affected. The vulnerability applies to all platforms supported by Chrome where extensions can be installed, including Windows, macOS, and Linux.
Risk and Exploitability
Chromium rates this issue as Low severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity. The likely attack vector involves a user installing a malicious extension designed by the attacker; the attacker then exploits the race condition to override system access controls. Because the flaw is tied to extension installation, it requires the user to allow the add‑on, so the risk is mitigated by cautious extension management.
OpenCVE Enrichment