Impact
The vulnerability lies in the Safe Browsing component of Google Chrome, where an inappropriate implementation that maps to CWE-693 allows a remote attacker to bypass the Safe Browsing protection when handling a malicious file. The weakness permits a malicious file to be considered safe by the browser, enabling the user to download or open it without the usual warning, potentially allowing malware execution. The impact is that a user could unknowingly install software that has been flagged as dangerous by the Safe Browsing database, which undermines the browser’s security guarantees and could lead to compromise of the host system.
Affected Systems
Google Chrome – any version prior to 149.0.7827.53 is affected. No other product or vendor is listed as impacted.
Risk and Exploitability
Chromium rates the issue as low severity, reflected in a CVSS score of 4.3. The EPSS score is less than 1% and the vulnerability is not in the CISA KEV catalog. Nonetheless, the attack vector remains a remote attacker successfully delivering a malicious file that is treated as safe by the browser. The threat enables potential malware execution upon user interaction, but the exploit requires user action and is therefore not highly likely to succeed without exploitation of additional vectors.
OpenCVE Enrichment
Debian DSA