Impact
Improper privilege management in the Actor component of Google Chrome before version 152.0.7977.65 permits a remote attacker who uses social engineering to deliver a specially crafted HTML page to elevate privileges or bypass system access restrictions. The flaw is a CWE‑269 issue and does not provide arbitrary code execution. Rather, it can enable an attacker to manipulate the browser environment with higher authority than intended, potentially compromising user data confidentiality or integrity through unauthorized access.
Affected Systems
All installations of Google Chrome running any version earlier than 152.0.7977.65 are affected, across all platforms where the Actor component is present. The issue applies to the stable channel releases at the time of the advisory.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.8 indicates a critical severity, suggesting that exploitation would grant significant privileges via a crafted HTML page and social engineering. While the attack vector remains remote, the risk is elevated due to the high severity rating and the possibility of bypassing system access restrictions. Applying the vendor patch remains the most effective protection.
OpenCVE Enrichment
Debian DLA
Debian DSA