Impact
Inappropriate implementation in the Chrome Extensions component allows a malicious extension crafted by an attacker with privileged network access to run arbitrary code within the browser’s sandbox. The flaw carries a moderate‑high severity rating (CVSS 7.1) according to the CVSS metric, while Chromium’s internal severity label marks it as Low. This weakness represents improper permission handling that permits code execution where it should be disallowed.
Affected Systems
Google Chrome versions older than 149.0.7827.53 are affected. The issue appears in the stable channel release for desktop prior to that build. No other Chrome products or major components are reported as impacted.
Risk and Exploitability
The CVSS score is 7.1, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been observed. The EPSS score of <1% indicates a very low probability of exploitation, supporting the view that public exploitation is unlikely. An attacker would need privileged network access to deliver a malicious extension. The impact of any successful exploit remains confined to the sandbox.
OpenCVE Enrichment
Debian DSA