Impact
An integer overflow in the CredentialProvider component of Google Chrome on Windows allows an attacker who has already compromised the renderer process to exploit a crafted HTML page and gain OS‑level privileges. The flaw permits the attacker to bypass standard access controls and execute arbitrary code with elevated rights. The weakness involves an integer overflow (CWE‑190) and a related buffer overrun condition (CWE‑472).
Affected Systems
The vulnerability affects Google Chrome versions on Windows that are earlier than 149.0.7827.53. No other platforms or product variants are documented as affected.
Risk and Exploitability
The required precondition is a compromised renderer process, implying that the attacker must have loaded malicious content into the browser. Chromium classifies the issue as Medium. EPSS is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a lower immediate exploitation probability. Nonetheless, once the renderer is compromised, the escalation path is reliable, and the impact could extend to full system compromise if the attacker succeeds.
OpenCVE Enrichment
Debian DSA