Impact
Improper input validation in the Safebrowsing component of Google Chrome, identified as a CWE‑20 flaw, enabled a remote attacker to bypass system access restrictions by presenting a specially crafted file. The vulnerability allows the attacker to gain elevated privileges on the affected system simply by having the user open the malicious file, with no additional local knowledge required. The Chromium project rates the flaw with a medium severity level, indicating potential for elevated privileges upon processing of the malicious file.
Affected Systems
All Chrome browsers on every platform running any version prior to 152.0.7977.65 are susceptible. The issue was addressed in the 152.0.7977.65 update released to the stable channel.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 4.3, indicating a medium severity rating, and the fact that the flaw allows privileged access without user interaction suggests a moderate to high exploitation risk when a malicious file can be delivered. No publicly known exploitation campaigns have been reported, but the absence of a KEV listing does not lessen the need for timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA