Insufficient policy enforcement in Extensions in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Insufficient policy enforcement in Extensions in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 42.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 42.00 |
VPI formula vpi-v1
This CVE is referenced in a KISA security bulletin (Korean only).