Chromium
cpe:2.3:a:chromium:chromium:*:*:*:*:*:*:*
- < 132.0.6834.83
A privilege escalation vulnerability has been identified in the Extensions component of Google Chrome, affecting versions prior to 132.0.6834.83. The issue arises from insufficient data validation, which allowed a remote attacker to exploit specific user interface interactions. By convincing a user to engage in these gestures, the attacker could execute a crafted HTML page that escalated privileges within the browser.
Exploitation of this vulnerability allows for unauthorized privilege escalation within the browser, potentially enabling malicious extensions to access restricted local files or resources.
The vulnerability can be reproduced by installing a malicious Chrome extension that requests access to file URLs. After disabling the default local file access restrictions, the extension can use the Chrome DevTools API to bypass these restrictions and access sensitive files, such as the hosts file, by manipulating the URL protocol getter. This exploitation requires user interaction with the DevTools sources panel.
Users can update to Google Chrome version 132.0.6834.83 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.