Impact
A flaw in Google Chrome’s WebUI authorization allows a remote attacker who has already compromised the renderer process to craft an HTML page that may execute arbitrary code outside the sandbox. The vulnerability was rated with a CVSS score of 8.3, indicating a high‑impact problem that can lead to full system compromise if successful.
Affected Systems
Google Chrome browser prior to version 153.0.8010.47 is affected. The issue exists in all desktop builds of Chrome with the vulnerable WebUI implementation.
Risk and Exploitability
The EPSS score is below 1%, suggesting that exploitation probability is low, and the vulnerability is not currently listed in CISA KEV. In practice the attacker would need to serve malicious content that gains control of the renderer process and then exploit the weakened authorization in the WebUI to escape the sandbox. If successful, the attacker could run code with local user privileges or potentially higher, depending on the sandbox configuration.
OpenCVE Enrichment