Impact
Incorrect authorization handling for USB devices in Google Chrome prior to version 152.0.7977.65 allows an attacker who has already compromised the renderer process to potentially escape the sandbox and execute arbitrary code on the host. The vulnerability manifests as a privilege escalation flaw (CWE-863) that can be triggered by a crafted HTML page and leveraged through social engineering. If successful, the attacker could gain full control of the system, bypassing Chrome’s sandboxed environment.
Affected Systems
All installations of Google Chrome running any version older than 152.0.7977.65 on supported operating systems are affected. This includes desktop builds for Windows, macOS, Linux, and Android.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3 and is rated as high severity by Chromium’s internal scoring, indicating a significant impact. The EPSS score is < 1%, indicating a low but nonzero exploitation probability, but the combination of remote code execution potential and the need for a renderer process compromise suggests meaningful exploitability in environments lacking strong process isolation or where attackers can persuade users to open malicious content. The vulnerability is not listed in the CISA KEV catalog, but its existence in a widely deployed browser warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA