Impact
The vulnerability is an inappropriate implementation in the Chrome updater on macOS that allows a local attacker who can place a malicious file to trigger the updater and gain operating‑system level privileges. The flaw relates to CWE‑269 (Privilege Escalation) and can let a user obtain full system control, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Google Chrome users on macOS with versions prior to 151.0.7922.72 are affected. The update to 151.0.7922.72 and later resolves the issue.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Exploitation requires local access and a crafted file, making it a local privilege escalation with moderate to high technical impact and low probability of real‑world abuse.
OpenCVE Enrichment
Debian DLA
Debian DSA