Impact
Improper input validation in Chrome's Safe Browsing service allows a crafted file to bypass system access restrictions. The flaw is identified as CWE‑20. Chromium rates the vulnerability as medium severity, potentially enabling unauthorized file access or privilege escalation when a user opens the malicious file.
Affected Systems
All installations of Google Chrome that are older than version 152.0.7977.65 for desktop operating systems—Windows, macOS, and Linux—are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity vulnerability, and the EPSS score shows a very low exploitation probability (<1%). The vulnerability is not listed in CISA's KEV catalog. The likely attack path is inferred from the description: an attacker would create a malicious file that, when opened by a user, triggers the Safe Browsing validation and bypasses existing system access controls. This inferred vector requires user interaction but could grant the attacker elevated privileges on the local machine.
OpenCVE Enrichment
Debian DLA
Debian DSA