Impact
The vulnerability is an incorrect authorization in the HID (Human Interface Device) subsystem of Google Chrome prior to 154.0.8037.57. A remote attacker who has already compromised the renderer process can deliver a crafted HTML page that bypasses system access restrictions. This flaw allows the attacker to perform actions normally restricted to authorized processes, potentially granting them broader system access. The weakness is classified as an authorization bypass (CWE‑863).
Affected Systems
Google Chrome versions earlier than 154.0.8037.57 are affected. Systems running any pre‑154 release of the stable channel are at risk, including desktop distributions that have not yet applied the September 2026 update.
Risk and Exploitability
The flaw carries a medium severity rating from Chromium. No CVSS score is available, and the EPSS score is not listed, indicating that the exploitation probability is currently unknown. The vulnerability is most likely to be exploited by an attacker who first gains remote code execution in the renderer process, after which the crafted HTML page can be served to bypass authorization checks. Because the condition requires a prior compromise of the renderer, the attack vector is a combination of remote code execution and privilege escalation. The flaw is not listed in the CISA KEV catalog, so no widespread exploitation has been publicly reported.
OpenCVE Enrichment
Debian DSA