Impact
An incorrect authorization check in the Chromoting component of Google Chrome for Windows allows a local attacker to bypass system access restrictions by executing a local program. This flaw is marked as medium severity by Chromium and maps to CWE-863, which represents the use of insufficient authority for access control. If exploited, the attacker could gain elevated control over Chrome’s remote‑desktop capabilities, potentially accessing user sessions or sensitive data within the browser.
Affected Systems
Google Chrome on Windows versions older than 152.0.7977.65 is affected. Users running these outdated installs may trigger the issue by launching a local program that activates the Chromoting feature.
Risk and Exploitability
The vulnerability requires local code execution and does not depend on network access. The CVSS score of 7.1 indicates moderate-to-high severity. The EPSS score is < 1%, suggesting a low probability of exploitation in the wild. Because the issue is not listed in CISA’s KEV catalog, public exploitation probability is uncertain. However, a local attacker who has ability to run code on a user’s machine could immediately use the bypass to gain elevated Chrome Remote Desktop privileges. The medium severity rating indicates a meaningful risk in a compromised or privileged context.
OpenCVE Enrichment
Debian DLA
Debian DSA