Impact
A race condition in the Chrome updater on Windows allows a local attacker to execute code outside the browser sandbox, granting them the ability to run arbitrary binaries or modify system settings. The vulnerability was evaluated by Chromium as high severity, reflecting the potentially critical impact on a user’s machine if exploited. The flaw arises when multiple threads access and modify shared state in the updater concurrently, enabling an attacker to influence its decision logic.
Affected Systems
Affected are installations of Google Chrome on Windows running any version prior to 153.0.8010.36. The specific patch that fixes the issue is distributed in the 153.0.8010.36 update and later releases.
Risk and Exploitability
The attack requires a local attacker with some user privileges to trigger the race, but once the race is exploited an attacker can escape the sandbox to obtain a full user’s access to system resources. The CVSS score is 8.1 and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog, yet its high severity rating and the possibility of local privilege escalation present a significant risk in environments where users have local write access to Chrome’s updater executable.
OpenCVE Enrichment
Debian DLA
Debian DSA