Impact
The vulnerability is an improper state validation in the Chrome installer that allows a remote attacker to create a crafted HTML page that bypasses system access restrictions. Because the installer does not properly check its state before performing privileged actions, the attacker can elevate privileges or execute code with higher privileges. This weakness is identified as CWE-754 and is rated Medium severity in Chromium's classification.
Affected Systems
All editions of Google Chrome released before 153.0.8010.36 are affected. This includes every platform that ships Chrome with a version less than 153.0.8010.36.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 4.3, which is considered Low according to standard scales but is labeled Medium severity by Chromium's internal assessment. The EPSS score is less than 1%, indicating a very low probability of exploitation. It is not listed in CISA's KEV catalog. The attack requires a remote attacker to host or serve a crafted HTML page that interacts with the Chrome installer. Successful exploitation would allow the attacker to bypass system access restrictions, potentially granting elevated privileges to the user's account or the entire system. Although the precise likelihood is difficult to quantify, the remote attack vector and the ability to elevate privileges present a realistic risk to users who open malicious HTML content from untrusted sources.
OpenCVE Enrichment
Debian DLA
Debian DSA