Impact
A flaw in the TabStrip authorization logic allows a remote attacker who has already compromised the renderer process and uses social engineering to deliver a specially crafted web page to potentially execute code outside Chrome’s sandbox. The vulnerability stems from improper authorization checks, enabling the attacker to perform actions that are normally restricted to privileged code paths.
Affected Systems
The flaw affects Google Chrome on desktop platforms, specifically any installation of Chrome prior to revision 152.0.7977.75. Users running those versions are at risk until they upgrade.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3, indicating a high impact. The EPSS score is < 1%, indicating a very low likelihood of exploitation. Exploitation requires an attacker to first compromise the renderer process and then lure a user to open a maliciously crafted HTML page, so the overall likelihood is limited but plausible. Successful exploitation would give the attacker code execution outside the sandbox with the privileges of the renderer.
OpenCVE Enrichment
Debian DLA
Debian DSA