Impact
A flaw in authorization logic for Chrome extensions allows a crafted extension to gain elevated privileges. Remote attackers can supply a malicious extension and rely on social engineering to have users install it, thereby bypassing normal system access restrictions.
Affected Systems
Google Chrome released before 152.0.7977.65 on the stable channel is affected. Any device running those versions of Chrome is vulnerable.
Risk and Exploitability
The vulnerability carries a Medium severity rating in Chromium security, reflected by a CVSS score of 4.3 and an EPSS score of less than 1%. Because the attack vector relies on a user installing a malicious extension, the risk depends on successful social engineering. The flaw is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA