Impact
The vulnerability is a type confusion in XML parsing: the parser treats data as a different type than intended, allowing a remote attacker to supply crafted content that can cause arbitrary code to execute while running inside Chrome’s sandbox. This flaw could lead to a full compromise of the browser session or user data if the attacker’s code runs successfully.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 on desktop platforms are affected. No specific operating systems or architectures are listed, but the attack requires the vulnerable browser to process the crafted HTML page.
Risk and Exploitability
The CVSS assessment classifies the issue as high severity, and the EPSS score is not publicly available. The flaw is not listed in CISA’s KEV catalog. Because it requires delivery of a crafted HTML page, the most likely attack vector is a remote web page or malicious email attachment that the user opens in a vulnerable Chrome instance. The vulnerability occurs within the sandbox, so achieving a full system compromise would require a separate sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA