Impact
In Chrome for Windows, a flaw in the CredentialProvider service allows a local user to supply a specially crafted file that the elevated service processes, resulting in execution with system privileges. This issue falls under the improper privilege management category (CWE‑269) and can elevate a normal user to administrator level. The flaw is limited to local attacks and requires the user to place malicious content in Chrome's credential directories, but the impact is elevation of privilege on the compromised machine.
Affected Systems
All Windows installations of Google Chrome released before version 150.0.7871.47 are affected. Since the CredentialProvider runs with elevated rights, any user with local access to the machine can exploit the issue by placing a malicious file in the directories monitored by the service.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity, but the EPSS <1% indicates a very low likelihood of exploitation at this time. Based on the description, the likely attack vector involves a local attacker placing a malicious file in the directories monitored by the CredentialProvider, requiring local access to the machine. The issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation. Nonetheless, the potential to gain system privileges warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA