Impact
An incorrect authorization check in the Downloads module of Google Chrome allows a remote attacker to bypass system access restrictions by presenting a crafted HTML page. The flaw exists in all Chrome builds prior to version 152.0.7977.65 and relies on user interaction with a malicious page. The vulnerability allows unauthorized manipulation of download controls and is rated medium by Chromium's security team.
Affected Systems
All builds of Google Chrome older than 152.0.7977.65 on any operating system are affected.
Risk and Exploitability
Chromium classifies this issue as medium severity (CVSS score 5.4) and it is not listed in CISA's KEV catalog. EPSS score is < 1%, so exploitation probability is very low. The attack requires a victim to open or interact with a malicious HTML page, so social engineering is the primary exploitation scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA