Impact
An authorization flaw in the Network component of Google Chrome permits a remote attacker who has compromised the renderer process to bypass system access controls through a crafted HTML page. The vulnerability allows the attacker to perform network operations that are normally restricted, potentially exposing sensitive system resources. The weakness maps to CWE‑863, indicating a failure to enforce proper access checks.
Affected Systems
Google Chrome versions prior to 155.0.8059.39 are affected. The flaw exists in the Network module of the browser, impacting all installations of Chrome that have not applied the latest update. Both consumer and enterprise deployments are susceptible if the affected version is used.
Risk and Exploitability
The CVE does not have an EPSS score; no KEV listing is present, implying a moderate exposure level. The attacker must already have control over a renderer process, which typically requires delivering malicious content or exploiting another vulnerability to achieve. Once the renderer is compromised, the attacker can use the flaw to elevate privileges and access the system beyond intended boundaries. Given the medium Chromium severity rating and lack of active exploitation reports, the immediate risk is considered moderate but mitigable by applying the patch.
OpenCVE Enrichment