Impact
Insufficient validation of untrusted input in the Safe Browsing component of Google Chrome allows a remote attacker to bypass discretionary access control with a crafted file. The flaw is mapped to CWE‑1289 and CWE‑20; it permits an attacker to access or modify system resources they should not have permission to control, effectively granting elevated privileges within the user's environment.
Affected Systems
Google Chrome desktop builds based on Chromium versions before 151.0.7922.72 are affected. The issue applies to all supported operating systems that ship the Chrome browser in the stable channel updated by Google.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, and the EPSS score of less than 1% shows a low likelihood of active exploitation. The vulnerability is not listed in CISA's KEV catalog, indicating no known widespread attacks. The likely attack vector is remote; a malicious file must be delivered and opened or processed by the user, after which discretionary access controls can be bypassed.
OpenCVE Enrichment
Debian DLA
Debian DSA