Impact
A local attacker who has compromised the renderer process can exploit an incorrect reference resolution flaw in Chrome extensions on macOS, allowing the execution of arbitrary code beyond the sandbox. The weakness is rooted in improper reference handling (CWE-386) and improper privileged escalation (CWE-706).
Affected Systems
Google Chrome for macOS versions earlier than 153.0.8010.47 are affected; the issue is observed on the desktop client and impacts any user running potentially compromised extensions.
Risk and Exploitability
The CVSS score of 8.1 and an EPSS score of less than 1% suggest a low but non‑zero likelihood that a local attacker can compromise the renderer process. This is not a remote or network‑based exploit, but local malware or a privileged user could leverage it. The vulnerability is not listed in CISA’s KEV catalog, reducing immediate exposure risk but not eliminating the need for remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA