Impact
The vulnerability stems from incorrect reference resolution in the Passwords module of Google Chrome before version 152.0.7977.65. It allows a remote attacker to create a crafted file that, when processed by the browser, resolves references incorrectly and bypasses system access restrictions. This flaw could grant an attacker unauthorized access to local system resources and is classified as CWE-706 (Incorrect Authorization).
Affected Systems
Google Chrome browsers on any platform where Chrome is installed and running a version earlier than 152.0.7977.65 are affected. The issue resides in the Passwords feature and impacts systems that store or retrieve passwords through Chrome.
Risk and Exploitability
Chromium rates this issue as medium severity with a CVSS score of 4.3, the EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must deliver a crafted file to the user, who then opens or processes it; no additional interaction beyond file consumption is required. The risk is limited to environments where such files can be introduced, but the lack of exploitation data means the likelihood of real‑world attacks remains uncertain.
OpenCVE Enrichment
Debian DLA
Debian DSA