Impact
This vulnerability is an improper implementation in the Enterprise edition of Google Chrome that allows a local attacker who has physical access to the device to gain higher privileges than intended. It is a privilege escalation flaw associated with CWE-266 and CWE-269. The issue does not affect network traffic or remote users; it requires that the attacker can reach the device in person.
Affected Systems
Affecting Google Chrome Enterprise installations in any revision before 149.0.7827.53. The exposed weakness is present in the policy enforcement code that manages local accounts on Windows, macOS, and Linux systems.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, which indicates a low probability of exploitation. The CVSS score of 6.1 indicates a moderate severity level. Exploitation requires local physical access and no network or user interaction beyond that. Because the attack vector is local and requires physical presence, the overall risk to an organization depends largely on its controls for device access.
OpenCVE Enrichment
Debian DSA