Impact
A race condition exists in the Core component of Google Chrome versions prior to 153.0.8010.47. It allows an attacker who already controls the renderer process to escape the sandbox and execute arbitrary code on the host. The vulnerability is classified as a race condition (CWE‑367 and CWE‑368) and scored 8.3 on CVSS, indicating a high severity if exploited.
Affected Systems
Google Chrome versions older than 153.0.8010.47 on all supported operating systems (Windows, macOS, Linux) are susceptible.
Risk and Exploitability
Exploiting the flaw requires an attacker to compromise the renderer process, usually through a malicious webpage that triggers the race condition. Once the renderer is compromised, the attacker can run code outside the sandbox. The CVSS score of 8.3 signals a high impact. The EPSS of less than 1% indicates that exploitation is presently unlikely, and the vulnerability does not appear in the CISA KEV catalog. Nonetheless, systems running vulnerable versions remain at risk if they process potentially malicious web content.
OpenCVE Enrichment
Debian DLA
Debian DSA