Impact
The vulnerability is an authorization flaw in Chrome’s getUserMedia API that allows a malicious webpage to request and collect camera or microphone data without the user’s explicit permission. Because the check is performed incorrectly, a remote attacker can trick the browser into providing sensitive media streams from a victim’s device. The flaw is classified as Chromium's medium severity, indicating a risk of confidential data exposure rather than code execution or system takeover.
Affected Systems
Google Chrome browsers running any stable channel release prior to 152.0.7977.65 are affected. Any user who has not upgraded to this version is potentially vulnerable to attack via a crafted HTML page served over the network.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score is < 1%, showing a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via a web page that the user visits; the attacker does not need elevated privileges or local access. If unpatched, an attacker could use the exposed media stream to obtain confidential video or audio data, compromising privacy.
OpenCVE Enrichment
Debian DLA
Debian DSA