Impact
Insufficient policy enforcement in Google Chrome extensions allows a compromised renderer process, combined with social engineering, to escape the sandbox and run arbitrary code. The vulnerability is categorized as CWE-807 and can lead to remote code execution. The flaw can be triggered by a crafted HTML page that the attacker delivers through a link or embed, and it exists only in versions prior to Chrome 153.0.8010.36.
Affected Systems
Google Chrome users running any version earlier than 153.0.8010.36 are potentially affected regardless of operating system. All desktop Chrome installations that had extensions installed during the affected release window are at risk. No specific vendor or product version exclusions are noted beyond the version cutoff.
Risk and Exploitability
Because the vulnerability requires an attacker to compromise the renderer process and rely on social engineering, the attack surface is limited but still notable. The EPSS score is less than 1% and the vulnerability is not listed in CISA's KEV catalog. Chromium rates the issue with a CVSS score of 8.3, indicating high severity and a clear possibility of remote code execution if the conditions are met.
OpenCVE Enrichment
Debian DLA
Debian DSA