Impact
An incorrect authorization check in Google Chrome’s Media component on Windows allows a remote attacker, who has already compromised the renderer process, to bypass system access restrictions by serving a specially crafted HTML page. The flaw is classified as CWE‑863 (Incorrect Authorization) and could enable the attacker to read or modify resources normally protected by system policies. The Chromium security team rates the severity as low, yet the capability to override access controls may have significant impact on confidentiality and integrity of system data.
Affected Systems
The vulnerability affects Google Chrome on Windows running versions prior to 152.0.7977.65. Any installation of Chrome within that version range and platform is potentially exposed.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation at this time. However, the requirement that the attacker has already compromised the renderer process increases complexity. If such compromise occurs—through malware or other vectors—the attacker can exploit the flaw by loading a malicious HTML page that accesses protected media resources. While the overall CVSS score of 6.5 indicates medium severity, the potency of bypassing system access controls warrants attention and remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA