Impact
A race condition in the CredentialProvider module of Google Chrome on Windows can be triggered by a local malicious file, allowing an attacker to gain operating‑system level privileges. The flaw is classified as CWE‑362 and CWE‑367, indicating a timing issue and a potential deadlock that can be exploited on a system already compromised or when a privileged user runs a specially crafted file.
Affected Systems
Google Chrome running on Windows, any version prior to 151.0.7922.109. Users of older builds are vulnerable; the issue does not affect other operating systems or newer Chrome releases.
Risk and Exploitability
The vulnerability has a CVSS score of 7.4, indicating a high severity level assigned by Chromium. EPSS score of <1% indicates a very low exploitation probability, and it is not listed in CISA's KEV catalog. The attack vector is local and requires the attacker to have write access to create the malicious file. If successful, the attacker achieves full system privilege on the affected machine.
OpenCVE Enrichment
Debian DLA
Debian DSA