Impact
The vulnerability allows a privilege elevation fault in the Import feature of Google Chrome versions prior to 151.0.7922.173. A remote attacker can craft a file and persuade a user to import it, at which point the browser can execute code outside its sandbox, enabling the attacker to run arbitrary code on the victim’s machine with the user’s privileges and potentially fully compromise the host system. The weakness is identified as CWE‑250 and CWE‑641.
Affected Systems
Affected editions are Google Chrome web browsers before version 151.0.7922.173 on any platform that supports the Import function. The issue does not appear in newer releases and is not present in earlier major versions beyond the listed threshold.
Risk and Exploitability
Chromium’s native severity assessment rates the issue as High, with a CVSS score of 8.8 indicating a high likelihood of significant impact. The EPSS score is < 1% and the issue is not listed in CISA KEV. The attack likely requires social engineering to convince users to import a malicious file. Once executed, code runs outside the sandbox, giving the attacker control over the host system. Because of the lack of public exploitation data, the likelihood is uncertain, but the severity warrants defensive action.
OpenCVE Enrichment
Debian DLA
Debian DSA