Impact
Chrome provides SiteSettings to control permissions such as camera, microphone, and site access. An incorrect authorization check in the SiteSettings component allowed a remote attacker to create a crafted HTML page that could modify these settings, effectively bypassing system access restrictions. This flaw is a CWE‑863 authorization bypass that lets malicious content change security settings without user consent, potentially granting the attacker higher privileges or access to protected data.
Affected Systems
All Chrome releases prior to version 152.0.7977.75 are impacted. Users who have not upgraded to this or later versions are at risk.
Risk and Exploitability
The Chromium severity is listed as Medium. No EPSS score is currently available, and the vulnerability is not present in the CISA KEV catalog. Because the issue requires delivery of a crafted HTML page, the likely attack vector is a remote or local web page that the user opens in Chrome. Attack conditions include the user enabling SiteSettings changes; once the malicious page is loaded, the attacker can alter or circumvent system access controls. Limited exploit data makes precise likelihood uncertain, but the medium severity indicates a non‑negligible risk.
OpenCVE Enrichment