Impact
The vulnerability is caused by an uncontrolled search path element in the CredentialProvider component of Google Chrome on Windows. A local attacker who can run arbitrary programs can manipulate the search path so that Chrome loads and executes malicious DLLs, enabling code execution outside the Chrome sandbox. The weakness corresponds to CWE-427 (Uncontrolled Search Path Element) and is documented as having medium severity by the Chromium security team.
Affected Systems
Windows operating systems running Google Chrome versions prior to 153.0.8010.36 are affected. Update to Chrome 153.0.8010.36 or later, which includes the security fix, to eliminate the flaw.
Risk and Exploitability
The advisory now indicates a CVSS score of 8.1, which corresponds to high severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation or absence of reported attacks. Because this flaw requires a local attacker with the ability to execute programs, it would likely be exploited only after the attacker has gained local access or user credentials. As such, the risk of exploitation is moderate. Patching is strongly recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA