Impact
Missing authorization in the Network component of Google Chrome before 152.0.7977.65 allows a remote attacker to bypass system access restrictions via a crafted HTML page. The flaw permits unauthorized access to privileged browser operations without proper permission checks, potentially exposing sensitive data or enabling additional attacks.
Affected Systems
Google Chrome browsers on all platforms running versions earlier than 152.0.7977.65 are affected. Versions 152.0.7977.65 and later contain the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating medium severity. An attacker can host a malicious HTML page that, when viewed by a user, triggers unverified network requests that bypass system access controls. The EPSS score is <1% and the flaw is not listed in CISA KEV, indicating limited public exploitation data. Nonetheless, the ability to bypass system access could lead to privilege escalation or data exposure if the malicious content can reach the targeted machine.
OpenCVE Enrichment
Debian DLA
Debian DSA