Impact
A missing authorization check in the Actor component of Google Chrome allowed a malicious actor to exploit a crafted HTML page. The flaw lets a remote attacker bypass system access restrictions, effectively elevating privileges without proper permission validation. The weakness is identified as an authorization gap (CWE‑862).
Affected Systems
This vulnerability affects Google Chrome versions earlier than 155.0.8059.39. Any installation of Chrome that has not been upgraded to 155.0.8059.39 or later is potentially exploitable.
Risk and Exploitability
The flaw is low severity according to Chromium, but it can be leveraged through social engineering. A victim must visit a malicious HTML page, after which the attacker can inject malicious content or commands. With no EPSS score available and the vulnerability not listed in the CISA KEV catalog, the modeled exploit probability is uncertain. However, because the attack requires only a crafted page viewed in the browser, the funnel of opportunity is wide and the privileged elevation result is powerful. The impact to confidentiality, integrity, and availability is significant if the attacker gains system-level access.
OpenCVE Enrichment