Impact
A race condition in Google Chrome before version 153.0.8010.36 allows a remote attacker to craft a malicious HTML page that can bypass system access restrictions. The vulnerability is classified as a medium‑severity Chromium bug, and the flaw can lead to unauthorized privilege escalation on the victim’s machine.
Affected Systems
All users running Google Chrome, any version older than 153.0.8010.36, on any supported operating system, are impacted.
Risk and Exploitability
Based on the description, the attacker must first deliver a malicious HTML page to the victim’s Chrome browser. The low EPSS score of < 1% and lack of a CISA KEV listing imply that this vulnerability is rarely exploited in the wild. The CVSS score of 5.3 indicates medium severity, and combined with the low exploitation probability, the overall risk is moderate. Nevertheless, an active exploitation would let the attacker bypass normal system access restrictions and achieve privilege escalation on the affected machine.
OpenCVE Enrichment
Debian DLA
Debian DSA