Impact
The vulnerability is a missing authorization flaw in Chrome’s InterestGroups feature that allows a remote attacker, once the renderer process is compromised, to bypass system access restrictions by supplying a specially crafted PDF file. The flaw does not directly execute code but enables unauthorized system access if the renderer is already compromised. The Chromium security team rated the issue as low severity.
Affected Systems
All users of Google Chrome versions prior to 152.0.7977.65 are affected. The flaw resides in the renderer process and impacts any platform where Chrome is installed and where PDF rendering is enabled.
Risk and Exploitability
EPSS score < 1% and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires compromise of the renderer process, the attack vector is limited to situations where a user has opened a malicious PDF in an untrusted context or where the renderer has been otherwise subverted. The CVSS score of 6.5 indicates a moderate risk, and the prerequisite conditions suggest that immediate attention is needed to prevent potential escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA