Impact
The vulnerability lies in the ImageCapture implementation of Google Chrome, allowing an attacker who has compromised the renderer process to gain elevated privileges. By exploiting this flaw, a malicious web page can perform operations beyond the browser sandbox, potentially accessing or modifying data on the host operating system. The weakness is a privilege escalation flaw (CWE-269) compounded by an authorization bypass that can be driven by user‑controlled input (CWE-648).
Affected Systems
All desktop users running Google Chrome versions earlier than 149.0.7827.53 are affected. The patch is included in Chrome 149.0.7827.53 and later releases. Other browsers or earlier Chrome releases are not impacted by this specific flaw.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw can lead to high impact due to privilege escalation, reflected by a CVSS score of 7.5. The overall risk remains limited by the requirement that the attacker already has compromised the renderer process.
OpenCVE Enrichment
Debian DSA