Impact
Improper quantity validation in the Tint feature of Google Chrome for macOS permits a remote attacker to craft an HTML page that triggers arbitrary code execution outside the browser sandbox. The vulnerability is rated with a CVSS score of 9.6, signifying a critical severity level, despite the Chromium project’s own labeling of its security severity as medium. An attacker who successfully exploits this flaw can run code with privileges beyond Chrome, potentially compromising the entire system. This issue stems from a classic input validation error (CWE‑1284).
Affected Systems
Google Chrome for macOS versions earlier than 153.0.8010.36 are affected. The problem occurs specifically in the Tint component and does not apply to other platforms or to later releases that contain the fix. Users operating the latest stable channel are protected.
Risk and Exploitability
The CVSS score of 9.6 classifies the flaw as critical, while the EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The vulnerability is not present in the CISA KEV catalog, suggesting no known active exploitation. The most probable attack vector involves a remote website delivering a malicious crafted HTML page that takes advantage of the unchecked quantity parameter to execute code outside Chrome’s sandbox. Any user who visits such a page before updating the browser runs the risk of complete system compromise. Overall, the combined severity and exploitation probability point to a moderate to high risk for unpatched systems.
OpenCVE Enrichment
Debian DLA
Debian DSA