Impact
Storage's reference resolution in Chrome on Windows could be subverted by a crafted HTML page, letting an attacker who had already compromised the renderer process run code outside the sandbox. The flaw enables arbitrary code execution, posing a severe breach of system integrity.
Affected Systems
Google Chrome on Windows versions before 153.0.8010.36 are vulnerable. Any installation using the old storage component is susceptible until the update lists the side. The issue afflicts the renderer process on desktop environments.
Risk and Exploitability
The vulnerability is scored low by Chromium, but it permits remote code execution via the renderer. The CVSS score of 8.3 indicates high severity, while the EPSS score is <1%, suggesting a low probability of exploitation, and the flaw is not listed in CISA's KEV catalog. If an attacker can supply a malicious page that reaches the compromised renderer, the attack vector is remote via a crafted HTML payload.
OpenCVE Enrichment
Debian DLA
Debian DSA