Impact
The vulnerability is a confused deputy flaw in the DataTransfer component of Google Chrome, which allows a remote attacker who already has control over the renderer process to execute arbitrary code outside the browser sandbox. The flaw can be triggered by a crafted HTML page that the compromised renderer processes, giving the attacker the ability to break out of the security context and run code with system privileges.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 are affected. Users of any operating system running these pre‑153.0.8010.36 builds are potentially vulnerable if a malicious webpage can inject code into the compromised renderer.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, and the EPSS score is below 1%, and the vulnerability is not listed in the KEV catalog. Exploitation requires that the attacker has already gained control of the renderer process, which typically means compromising a user’s browsing session or an injected script. Once that condition is met, the attacker can execute code outside the sandbox, potentially compromising the host system. Given the lack of a public exploit and the requirement for a pre‑existing compromise, the overall risk is moderate but should not be ignored.
OpenCVE Enrichment
Debian DLA
Debian DSA