Impact
Incorrect authorization in Chrome’s Network component allowed a remote attacker to bypass system access restrictions via a crafted HTML page. The flaw permits an attacker to gain unauthorized access to network‑level settings or capabilities normally protected by system restrictions, potentially escalating privileges or accessing sensitive network resources without user consent.
Affected Systems
All Google Chrome users on versions earlier than 152.0.7977.65 are potentially affected. The vulnerability exists across Chrome’s stable channel releases before the 152.0.7977.65 patch, regardless of operating system.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating a Medium severity, and an EPSS score of less than 1% suggests low likelihood of exploitation. Because the flaw requires a crafted HTML page to be served to an end‑user, exploitation likely needs social engineering or a compromised site to lure the victim into opening the page. While no known public exploits exist, the absence of a KEV listing does not negate the risk; the flaw still enables a serious privilege escalation if a user visits a malicious page.
OpenCVE Enrichment
Debian DLA
Debian DSA