Impact
An externally controlled reference in Google Chrome’s DevTools component can be supplied by an adversary through crafted network traffic. This flaw, identified as CWE‑610, allows an attacker to bypass system access restrictions enforced by the browser. The vulnerability could potentially enable the attacker to execute privileged actions or access restricted resources within the Chrome environment.
Affected Systems
Google Chrome desktop browsers on Windows, macOS, and Linux prior to update 154.0.8037.57 are affected. All users running an older stable channel version before this release are vulnerable until they apply the update.
Risk and Exploitability
Chromium labels the issue as Medium severity. No EPSS score is currently available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the victim to interact with or be subjected to malicious crafted traffic, typically via a socially engineered lure. Because the defect resides in a privileged component, the potential impact is the ability to bypass system access controls, but no publicly documented exploit is known at this time.
OpenCVE Enrichment
Debian DSA