Impact
An incorrect authorization check in Chrome’s USB handling allows a remote attacker to craft a malicious HTML page that invokes USB APIs. The attacker relies on social engineering to get a user to load the page, then Chrome permits USB access that should have been rejected, granting the attacker unauthorized system access. The vulnerability is identified as CWE‑863 and is graded as a medium severity flaw in Chromium’s internal scale.
Affected Systems
The flaw affects Google Chrome versions installed before 152.0.7977.65 on desktop operating systems. Users on earlier stable releases that have not yet applied the update are at risk until they upgrade to the patched build.
Risk and Exploitability
The CVSS score is 4.3, and the EPSS score is < 1%, so the exact exploitation probability is unknown. However, the vulnerability requires user interaction with a malicious web page, suggesting a remote social‑engineering vector rather than an automated attack loop. The flaw is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA