Impact
Inappropriate implementation in the Google Chrome Updater on Windows allows a local attacker to place a malicious file that the updater processes, which can result in OS‑level privilege escalation. The flaw is characterized as CWE‑284. An attacker gains system‑wide privileges by exploiting the updater's incorrect file handling.
Affected Systems
All Windows installations of Google Chrome older than version 150.0.7871.47 are affected. The vulnerability exists in the updater component of those releases.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA KEV. Nonetheless, with a CVSS score of 7.8 the flaw remains high severity for an attacker who can write to the updater’s directories. The attack requires local access and the ability to place a malicious file, after which the updater executes it with elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA