Impact
Improper input validation in Chrome’s DataTransfer component allows a remote attacker to bypass system access restrictions via a co‑installed application, enabling privilege escalation.
Affected Systems
Users running any version of Google Chrome before 152.0.7977.75 are affected.
Risk and Exploitability
The CVE has a high severity with a CVSS score of 9.8. The EPSS score is less than 1%, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector involves a social engineering approach that tricks a user into installing a co‑installed app capable of exploiting this flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA