Impact
The vulnerability is a memory corruption flaw in the V8 JavaScript engine of Google Chrome prior to version 153.0.8010.36. When a specially crafted Chrome extension is loaded, a remote attacker could trigger the fault and potentially execute arbitrary code within the browser’s sandbox. This flaw falls under CWE‑119, a classic buffer overflow that compromises data integrity and can be leveraged for remote code execution.
Affected Systems
The affected product is Google Chrome on desktop systems. Any installation of Chrome at or below version 153.0.8010.36 is vulnerable. The security advisory is for the stable channel; earlier channels may have higher versions, but the vulnerability specifically applies to the referenced build range.
Risk and Exploitability
The issue is rated as a low severity in Chromium’s own security chart, and no published EPSS score is available, indicating a lack of confirmed exploitation activity. The KEV catalog does not list this vulnerability, suggesting it is not widely used by threat actors yet. However, the exploit path remains viable: a malicious extension could be distributed via the Chrome Web Store or other channels, though this distribution channel is inferred from typical extension distribution practices, meaning users who install untrusted extensions may be at risk. The absence of a known patch until the new release means the window for exploitation exists until the update is applied.
OpenCVE Enrichment