Impact
The flaw resides in Chromoting, the Remote Desktop component of Google Chrome. On Windows versions prior to 152.0.7977.75 a local program can bypass the service’s authorization check, allowing execution of arbitrary binaries outside the browser sandbox. This results in local privilege escalation and gives the attacker full control over the compromised machine.
Affected Systems
Microsoft Windows systems that run Google Chrome versions older than 152.0.7977.75 are affected. Any installation of Chrome on Windows that has not yet been updated to the 152.0.7977.75 release or newer is vulnerable to this local privilege escalation attack.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, classifying it as high severity. Because the EPSS score is below 1% and the defect is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is currently low, yet the local privilege escalation remains significant for users who can run code locally. An attacker who can execute a benign program on the victim’s machine could leverage the broken authorization to run code with elevated privileges, effectively bypassing Chrome’s sandbox and gaining full system control.
OpenCVE Enrichment
Debian DLA
Debian DSA