Impact
The vulnerability, identified as an instance of CWE‑269 (Improper Privilege Management) and CWE‑303 (Improper Access Control), is found in the Cast component of Google Chrome. A flaw in how it handles incoming network traffic allows an attacker located on the same local network segment to bypass discretionary access control checks, resulting in unauthorized access to Chrome features or resources that should be restricted by policy.
Affected Systems
All Chrome releases prior to 149.0.7827.53 are affected. Users on Windows, macOS, or Linux should update to a supported build that includes the fix.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity, while the EPSS score of <1% suggests a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. This problem is categorized as CWE‑303, reflecting a failure to enforce proper access controls. Based on the description, the attack vector likely requires the attacker to be on the same local network segment and to send crafted Cast traffic. The claim that no public exploit currently exists and that the overall risk is modest is inferred; it is not explicitly stated in the CVE data. Nevertheless, remediation is recommended to prevent a discretionary access control bypass.
OpenCVE Enrichment
Debian DSA