Impact
An improper implementation in Chrome's CredentialProvider component for Windows allows a local attacker to place a malicious file that Chrome processes, causing the service to run with elevated privileges. This flaw involves improper privilege management (CWE-269) and results in privilege escalation on the local machine.
Affected Systems
All Windows installations of Google Chrome released before version 150.0.7871.47 are vulnerable, as the CredentialProvider service runs with elevated rights and processes files that can be supplied by a local user.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity, but the EPSS <1% indicates a very low probability of exploitation. Because it requires local presence and the ability to supply a malicious file processed by Chrome's CredentialProvider, the risk is moderate for unpatched systems. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The flaw exploits improper privilege management (CWE-269), enabling local privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA