Impact
A race condition exists in Chrome’s extension handling on macOS in versions prior to 153.0.8010.47. An attacker who has already compromised the renderer process and used social engineering can interact with the user interface to force the renderer to execute code outside the sandbox. This results in privilege escalation and full system compromise. The weakness is based on race conditions (CWE‑367 and CWE‑368).
Affected Systems
Chrome browsers on macOS earlier than version 153.0.8010.47.
Risk and Exploitability
The CVSS score of 8.3, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to already have control of the renderer process and to conduct a social‑engineering attack that prompts the victim to trigger a UI interaction. If these conditions are met, the attacker can run arbitrary code outside Chrome’s sandbox, compromising the entire operating system.
OpenCVE Enrichment
Debian DSA