Impact
Incomplete cleanup in Google Chrome’s network module before version 152.0.7977.82 permits a remote attacker to craft network traffic that bypasses the browser’s system access restrictions. The flaw is classified with a high severity rating, indicating a significant risk to confidentiality, integrity, or availability for users who rely on Chrome’s default security controls.
Affected Systems
All installations of Google Chrome released prior to version 152.0.7977.82 are vulnerable, regardless of operating system. The issue is confined to the browser’s network stack and affects any user who has not applied the latest update.
Risk and Exploitability
The vulnerability’s CVSS score of 9.1 and an EPSS score of less than 1 % suggest a low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the delivery of crafted packets over any network channel that Chrome processes, without requiring local code execution or elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA