Impact
A local authorization bypass in Google Chrome’s Updater on Windows prior to version 153.0.8010.36 permits a local attacker to run code with system privileges, escaping the browser sandbox. This flaw can allow the attacker to modify system files, install malware, or perform other high‑impact actions on the host. The weakness is classified as CWE-863 (authorization bypass).
Affected Systems
Google Chrome for Windows users running any version before 153.0.8010.36 are affected. Upgrades to 153.0.8010.36 or newer resolve the issue.
Risk and Exploitability
The vulnerability’s CVSS score of 8.1 indicates high severity. It is not listed in CISA KEV and its EPSS score is less than 1%, meaning current exploitation likelihood is very low but the flaw remains high risk if discovered. The attack requires local access; a user with privileges on the target machine can trigger the local updater to run arbitrary code outside Chrome sandbox. Due to lack of public exploits yet, the risk to the broader community remains limited, but the potential impact on the affected system is significant.
OpenCVE Enrichment
Debian DLA
Debian DSA