Impact
The vulnerability is a race condition in Chromoting, the Chrome Remote Desktop protocol. It allows a local attacker to execute arbitrary code with privileges that bypass the Chrome sandbox. The weakness is classified as CWE-367, a timing race, and results in a high severity risk of local code execution.
Affected Systems
Products impacted are Google Chrome running on Windows systems. Any installation of Chrome prior to version 153.0.8010.36 is vulnerable to the race condition and could be exploited to break out of the sandbox.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating a high severity, and an EPSS score of <1%, suggesting low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires local access to launch a program that triggers the race in Chromoting. The technique relies on precise timing and therefore is moderately difficult to engineer; once successful, the attacker can run code outside the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA