Impact
A flaw in the reference resolution logic used by Tracing in Google Chrome permits a local attacker on Windows systems to run arbitrary code outside the sandbox by influencing how a local program resolves tracing references. The vulnerability is a manifestation of improper access control (CWE‑706) and carries a high severity rating. If successfully exploited, the attacker could compromise the integrity and confidentiality of the host process and potentially other processes that the browser or its extensions interact with.
Affected Systems
Google Chrome on Windows prior to 153.0.8010.52 is impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates substantial potential impact, while the EPSS score of less than 1% shows a low probability of current exploitation in the wild. The vulnerability is not listed in CISA KEV. The attack scenario requires local access and a trusted local program to trigger the flawed reference resolution. No public exploit has been disclosed, but the low EPSS and absence from KEV suggest that the risk is moderate but still actionable.
OpenCVE Enrichment
Debian DLA
Debian DSA