Impact
The flaw is an inappropriate implementation in the Chromoting component of Google Chrome on Linux, which allows a remote attacker to send malicious network traffic that results in OS‑level privilege escalation. The impact is elevation of privileges on the host operating system, with a Chromium security severity of medium. The CVE description does not mention additional safeguards within Chrome for the affected operation.
Affected Systems
All users of Google Chrome on Linux running versions prior to 149.0.7827.53 are affected. The flaw resides in the Chromoting feature of the Chrome browser delivered by Google.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but because the attack vector is a remote network connection, exploitation is theoretically feasible for any attacker who can inject crafted traffic. The high CVSS score of 8.1 indicates a high severity rating and suggests non‑negligible risk, especially in environments where Chromoting is enabled and the browser is exposed to untrusted networks.
OpenCVE Enrichment
Debian DSA