Impact
The flaw is caused by incorrect reference resolution in Chrome extensions, allowing a remote attacker to craft malicious network traffic that can lead to execution of arbitrary code outside the browser sandbox. This is a client‑side input validation weakness (CWE‑706) that could compromise the entire host system if exploited.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 installed on desktop operating systems are affected.
Risk and Exploitability
According to the CVE description the vulnerability is rated Medium, yet the CVSS score of 9 indicates a high technical severity. The EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote network traffic directed at a vulnerable extension, and successful exploitation would break the sandbox and give the attacker code‑execution privileges on the victim’s machine. No publicly available evidence of exploitation has been reported, but the potential impact warrants prompt action.
OpenCVE Enrichment
Debian DLA
Debian DSA