Impact
The vulnerability resides in Chrome’s extensions system where an absent authorization check allows a compromised renderer process to send specially crafted network requests that can escape the sandbox and execute arbitrary code. This flaw permits code execution with the privileges of the user’s Chrome process, potentially compromising the entire system or user data. The flaw is classified with a medium severity in Chromium’s terminology, but its impact is significant due to the remote code execution capability.
Affected Systems
Any Google Chrome installation on desktop platforms running a version earlier than 153.0.8010.36 is affected. The issue targets the extensions component and the communication path between the renderer process and the network stack.
Risk and Exploitability
The CVSS score is 8.1, and the EPSS score is < 1%. The flaw has not been listed in the CISA KEV catalog. The attack requires an attacker to first compromise the renderer process, which implies local or elevation of privilege conditions, such as installing a malicious extension or exploiting a separate vulnerability to gain renderer control. Once the renderer is compromised, the attacker can send crafted network traffic to exploit the missing authorization and trigger code execution outside the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA