Impact
A race condition in the Chrome Updater on Windows allows a local attacker to execute arbitrary code outside the sandbox by manipulating a local program. The flaw is a typical concurrency problem that can be exploited to bypass sandbox protections, potentially giving an attacker full control over the affected system.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 on Windows are affected. This includes desktop installations where the updater runs with elevated privileges. No other vendors or products are currently cited.
Risk and Exploitability
The vulnerability can be leveraged by a local user or a program with local execution privileges. The CVSS score of 8.1 indicates a high severity, and the EPSS score is under 1%, suggesting low likelihood of exploitation in the wild, but the issue is not listed in CISA KEV. The Chromium severity is Medium, indicating a moderate risk if exploited. The attack vector is local, requiring the attacker to have access to a local program or the ability to execute code on the machine.
OpenCVE Enrichment
Debian DLA
Debian DSA