Impact
Missing authorization in the Network component of Google Chrome before 152.0.7977.65 allows a remote attacker who has compromised the renderer process to bypass system access restrictions by serving a specially crafted HTML page. This flaw can enable the attacker to read or modify files and data that normally would be protected by the operating system, effectively elevating privileges within the browser context. The Chromium severity is medium.
Affected Systems
All users running Google Chrome stable channel versions earlier than 152.0.7977.65 are affected. The issue is confined to the stable channel’s Network component and does not impact newer releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity, while the EPSS score of < 1% suggests a low likelihood of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Exploitation requires an attacker to first compromise the renderer process—common attack vectors include drive‑by downloads or malicious extensions. Once the renderer is compromised, a crafted HTML page can bypass the Network component’s authorization checks and access protected system resources. Because the initial renderer compromise is required and no public exploits are known, the overall risk remains moderate.
OpenCVE Enrichment
Debian DLA
Debian DSA