Impact
The vulnerability arises from an incorrect authorization check within Chrome’s DevTools. As a result, a remote attacker can serve a specially crafted HTML page that, when opened in the browser, bypasses sandbox boundaries and can run arbitrary code on the host machine. This flaw is a form of unauthorized access to privileged resources (CWE‑863) and, if exploited, could allow an attacker to compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Google Chrome users running any version older than 153.0.8010.36 are vulnerable. The issue is present in all platforms where DevTools remain enabled. Updating to Chrome 153.0.8010.36 or newer removes the flaw.
Risk and Exploitability
The flaw carries a CVSS score of 9.6, placing it in the Critical severity range, and the EPSS score is < 1%. The CVE notes that exploitation is possible via a network‑accessible crafted HTML page, which a remote attacker can host and serve to a victim. The vulnerability is not yet listed in CISA’s KEV catalog. Attackers would need to deliver a malicious page to the victim, but the remote nature of the attack means it could be leveraged in phishing or drive‑by scenarios. Given the high impact and the ease of delivery, organizations should treat this as a critical patching priority.
OpenCVE Enrichment
Debian DLA
Debian DSA