Impact
The vulnerability is an incorrect authorization flaw in the Chromoting component of Google Chrome on Windows. A local attacker can exploit the flawed check to execute arbitrary code outside the browser sandbox by running a local program that interacts with Chromoting. This allows the attacker to gain elevated privileges on the victim machine, effectively bypassing the intended security boundaries of Chrome. The weakness falls under CWE‑863, which addresses improper authorization mechanisms.
Affected Systems
Microsoft Windows systems running Google Chrome versions before the 152.0.7977.75 release are impacted. Any installation of Chrome on Windows that has not yet been updated to 152.0.7977.75 or newer is vulnerable to this local privilege escalation attack.
Risk and Exploitability
The exploit requires local access and a program that can interact with the Chromoting service, so it is not remotely exploitable. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the overall likelihood of widespread exploitation is currently undetermined. However, the potential impact for users who can run code locally and have administrative privileges is significant, allowing attackers to break out of the sandbox and execute code with elevated rights. The fill-in severity from Chromium is medium, suggesting moderate risk to affected systems.
OpenCVE Enrichment