Impact
An authentication flaw in Chrome’s Device feature allows a remote attacker, through a crafted HTML page, to bypass system access restrictions. By exploiting incorrect authorization checks (CWE-863), a malicious HTML page can be served to a user, enabling unauthorized access to device capabilities that should be protected within the browser. The effect is an escalation of privileges from a normal user to a higher level of system resource access.
Affected Systems
Google Chrome browsers running versions prior to 152.0.7977.65 are vulnerable. The issue affects the stable channel of Chrome on all supported operating systems until the stated fixed version is installed.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, rated as Medium severity, and is not listed in the CISA KEV catalog. Exploitation requires social engineering of the victim to load the malicious HTML, indicating that proactive user awareness and prompt updates are key defenses. While an attacker cannot achieve arbitrary code execution, the ability to lift system access restrictions poses a significant risk for targeted users. The EPSS score of < 1% indicates a very low probability of exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA