Impact
UI misrepresentation in the Linux Toolkit Theming of Google Chrome prior to version 152.0.7977.65 allows a remote attacker, through a crafted HTML page, to bypass system access restrictions. By exploiting this flaw, an attacker can trick a user into executing privileged actions outside the intended sandbox, effectively circumventing the operating system’s access controls. The vulnerability is not a direct code execution flaw, but it enables an attacker to elevate privileges through deception and social engineering.
Affected Systems
Google Chrome users operating on Linux with any version earlier than 152.0.7977.65 are affected. The issue resides in the Linux Toolkit Theming component, which processes rendered web content and can be manipulated via crafted HTML to misrepresent UI elements and cause privilege escalation.
Risk and Exploitability
The CVSS score is 5.4, and the EPSS score is 0.00305 (less than 1%), indicating very limited exploitation likelihood. The vulnerability is classified with low security severity by Chromium, and it is not recorded in the CISA KEV catalog. Nevertheless, the attack vector requires the user to open or interact with a malicious web page, meaning the risk is largely mitigated by user awareness but remains impactful if social engineering succeeds. Organizations should consider the potential for privilege bypass when evaluating risk for their Chrome deployments.
OpenCVE Enrichment
Debian DLA
Debian DSA