Impact
Injection within the DevTools component of Google Chrome permits an attacker who has already compromised the renderer process to execute arbitrary code outside the browser sandbox. This is a CWE‑74 input injection flaw. The flaw exists before Chrome version 153.0.8010.36, and the CVE description characterizes it as a high‑severity issue.
Affected Systems
All Google Chrome browsers older than 153.0.8010.36 are affected. Users of these releases should consider upgrading to remediate the vulnerability.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The CVSS score is 8.3. Exploitation requires an initial compromise of the renderer process; the attacker can then supply a malicious HTML page that triggers the DevTools injection. Because the flaw enables execution outside the sandbox, it poses a serious threat if the prerequisite conditions are met.
OpenCVE Enrichment
Debian DLA
Debian DSA