Impact
The flaw in Chrome’s extension handling leaves residual data after an extension is removed, allowing elevated privileges. An attacker who tricks a user into installing a malicious extension can take advantage of the residual data to elevate its privileges. The weakness is an incomplete cleanup, identified as CWE-459, without further compromise of the browser itself.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 on all supported operating systems. No specific platform distinctions are indicated by the data that predates the mentioned revision.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating medium severity. The EPSS score is less than 1 probability, and the flaw is not listed in the CISA KEV catalog. It is inferred that exploitation requires a remote engineering—to install a malicious extension. Once installed, the incomplete cleanup permits the extension to upgrade its privileges to those normally prohibited, potentially allowing system‑wide access. It is inferred that the attack path is plausible for users who are not diligent about extension provenance, although no public exploit code is documented.
OpenCVE Enrichment
Debian DLA
Debian DSA