Impact
A race condition exists in Chrome extensions on macOS versions before 153.0.8010.47. The flaw allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that can execute arbitrary code outside the browser sandbox. The vulnerability is classified as a High severity issue with a CVSS score of 8.3 and is associated with CWE‑367. If exploited, the attacker could gain privileges beyond the sandbox, potentially running code with system-level access.
Affected Systems
Google Chrome for macOS, specifically any version8010.47, is vulnerable. The issue was identified in the Chrome stable channel on macOS and applies to all installations using that channel before the specified patch.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector, as inferred from the description, requires an attacker to first compromise the renderer process – a scenario that might be achieved through a malicious extension or a compromised web page – after which the crafted HTML page can trigger the race condition. Given the high activity in the renderer process, the exploit would execute outside the sandbox, providing the attacker with persistence and elevated privileges. The low exploitation probability does not obviate the need for remediation, however.
OpenCVE Enrichment