Impact
Insufficient policy enforcement in Google Chrome’s Password Manager prior to 149.0.7827.53 allows a remote attacker to bypass discretionary access control by delivering a crafted HTML page. The flaw enables an attacker to read or alter stored passwords without the user’s knowledge, providing potential credential theft. Chromium lists the vulnerability as medium severity.
Affected Systems
All versions of Google Chrome older than 149.0.7827.53, including the desktop Stable channel, are affected. The issue applies to any installations that have not applied the 149.0.7827.53 release or later.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not included in CISA’s KEV catalogue. The CVSS score of 6.5 reflects medium severity. Attackers can exploit the flaw remotely by serving a malicious web page that the victim visits. Bypassing discretionary access control could expose stored credentials, but the exploit requires only access to the victim’s browsing session and does not need elevated privileges.
OpenCVE Enrichment
Debian DSA