Impact
The flaw is a race condition in the extensions subsystem of Google Chrome. When network packets are processed concurrently by multiple extension processes, crafted traffic can desynchronize internal state and cause a malicious payload to be executed. An attacker can thus run arbitrary code within the sandboxed environment of the extension.
Affected Systems
All users running Google Chrome versions older than 152.0.7977.65 are affected. This includes the stable channel released prior to that version, across all operating systems supported by Chrome.
Risk and Exploitability
The vulnerability is high severity as indicated by a CVSS score of 8.1, and the EPSS score is < 1%. It is not listed in CISA’s KEV catalog, indicating that widespread exploitation has not been reported. The likely attack vector is remote, requiring an active network connection capable of delivering crafted packets to the extension component. While the impact is sandbox escape, it is inferred that the attacker’s capabilities are limited to executing code within the sandboxed environment, as explicit capabilities such as local file access or privileged actions are not stated in the description.
OpenCVE Enrichment
Debian DLA
Debian DSA