Impact
Chrome’s WebUI authorization flaw allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that can execute code outside the sandbox. The weakness is an authorization bypass (CWE‑863) combined with improper authorization (CWE‑266), meaning that privileged actions are performed based on user‑controlled input that should not be trusted. This vulnerability carries a CVSS score of 8.3, indicating high severity and the possibility of full system compromise if successful.
Affected Systems
Google Chrome desktop versions prior to 153.0.8010.47 contain the vulnerable WebUI implementation. All builds of the stable channel before this revision are affected.
Risk and Exploitability
The EPSS score is below 1 %, suggesting a low exploitation probability, and the vulnerability is not listed in CISA KEV. In practice, the attacker would need to serve malicious content that gains control of the renderer process and then exploit the combined authorization weaknesses in the WebUI to escape the sandbox. If successful, the attacker could run code with the local user’s privileges or potentially higher, depending on the sandbox configuration. The attack vector requires an initial compromise of the renderer process; the flaw alone does not grant remote code execution from outside the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA