Impact
Improper input validation in Chrome’s DataTransfer component allows a remote attacker to bypass system access restrictions through a co‑installed application, enabling unauthorized actions that would normally be denied. The weakness is a classic input validation flaw categorized as CWE‑20 and is considered high severity by Chromium security. The attacker can cause the browser to treat privileged data as non‑privileged, which may facilitate further exploitation.
Affected Systems
Affected systems are users running any version of Google Chrome before 152.0.7977.75. No specific patches are listed in the input, but the advisory indicates that the issue is fixed in the 152.0.7977.75 release.
Risk and Exploitability
The CVE is rated high severity and appears in a major browser, so the potential impact is significant. EPSS data is unavailable, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector involves social engineering, such as phishing or malicious web content that lures a user to install a co‑installed app that can exploit the flaw.
OpenCVE Enrichment