Impact
A local attacker who has compromised the renderer process can exploit an incorrect reference resolution flaw in Chrome extensions on macOS, allowing execution of arbitrary code beyond the sandbox. The vulnerability is rooted in improper reference handling (CWE-386) and improper privileged escalation (CWE-706).
Affected Systems
Google Chrome for macOS versions earlier than 153.0.8010.47 are affected; the issue is observed on the desktop client and impacts any user running potentially compromised extensions.
Risk and Exploitability
The CVSS score of 8.1. EPSS score of less than 1% suggests low but non‑zero likelihood compromise of the renderer process, meaning it is not a network‑based remote exploit but could be leveraged by local malware or a privileged user. The vulnerability is not listed in CISA’s KEV catalog, which reduces the immediate exposure risk but does not eliminate the need for remediation.
OpenCVE Enrichment
Debian DSA