Impact
The vulnerability is found in the Cast component of Google Chrome. A flaw in its handling of incoming network traffic allows an attacker located on the same local network to bypass discretionary access control checks, resulting in unauthorized access to Chrome features or resources that should be restricted by policy.
Affected Systems
All Chrome releases prior to 149.0.7827.53 are affected. Users on Windows, macOS, or Linux should update to a supported build that includes the fix.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity, whereas EPSS data is unavailable and the issue is not listed in the CISA KEV catalog. Based on the description, the attack vector likely requires the attacker to be on the same local network segment and to send crafted Cast traffic. The claim that no public exploit currently exists and that the overall risk is modest is inferred; it is not explicitly stated in the CVE data. Nevertheless, remediation is recommended to prevent a discretionary access control bypass.
OpenCVE Enrichment