Impact
The vulnerability lies in the ImageCapture implementation of Google Chrome. A malicious web page can be crafted to execute privileged operations from a compromised renderer process, allowing an attacker to gain higher privileges than normally permitted by the browser and potentially the operating system. This flaw can lead to unauthorized data access or modification, but as the assigned severity is low, such elevation is likely limited to the scope of the renderer's privileges.
Affected Systems
All users running Google Chrome on desktop platforms with a renderer process version prior to image capture update 149.0.7827.53 are affected. The issue does not extend to other browsers or earlier Chrome releases that are already patched.
Risk and Exploitability
The EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, indicating limited observed exploitation. However, the flaw requires that an attacker already has compromised the renderer process, which is a non-trivial requirement. The low severity rating suggests that the overall risk remains modest, yet the privilege escalation potential warrants care. Without a specific exploit observed, the likelihood remains uncertain but should not be discounted.
OpenCVE Enrichment