Impact
A race condition in the Core component of Google Chrome, present in all releases before 153.0.8010.47, allows a malicious renderer process to break out of the sandbox and run arbitrary code on the host machine. This flaw can be triggered by a specially crafted HTML page viewed by an authenticated victim, and the stated cybersecurity severity is High. The vulnerability is classified as a race condition (CWE-367) and carries a CVSS score of 8.3, indicating a high potential impact if exploited.
Affected Systems
All installations of Google Chrome older than version 153.0.8010.47 are affected. The flaw resides in the Core subsystem of the browser and is not limited to any particular operating system, meaning that users on Windows, macOS, or Linux running a vulnerable build run the risk of code execution through a malicious webpage.
Risk and Exploitability
The CVSS severity indicates serious consequences, while the EPSS score of less than 1% suggests that the vulnerability is unlikely to be widely exploited at present, and it is not listed in the CISA KEV catalog. Exploitation requires the attacker to compromise the renderer process, which typically occurs through a malicious web page delivered to a user’s browser. Once the renderer is compromised, the attacker can execute code outside the sandbox, giving full system access. Given the low EPSS, the threat is moderate but non‑negligible, especially for users who visit untrusted sites or allow third‑party extensions that may inject content.
OpenCVE Enrichment