Impact
A flaw in Google Chrome’s WebUI allows a remote attacker who has compromised the renderer process to gain code execution privileges outside the usual sandbox. The vulnerability is triggered by a specially crafted HTML page that is delivered to the affected browser instance. Although Chrome labels the related security issue as medium severity, the potential outcome is the execution of arbitrary code with elevated privileges on the host machine.
Affected Systems
Google Chrome users running any version prior to 153.0.8010.36 are affected by this WebUI privilege escalation. The vulnerability applies to the desktop releases of the browser.
Risk and Exploitability
The attack vector requires a compromised renderer process and a crafted HTML page, indicating that the threat is limited to scenarios where the attacker can influence page content on the victim’s machine. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Because the flaw permits arbitrary code execution outside the sandbox, the risk of exploitation is significant if the conditions are met. The CVSS score is 8.3, indicating a high severity and suggesting a high risk for affected systems.
OpenCVE Enrichment
Debian DLA
Debian DSA