Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 148.0.7778.96 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| chrome | cert_advisory | 90% | |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft, added product Edge, and marked exploit as available and actively exploited.
Updated severity to CRITICAL, changed patch available version to 147.0.7727.138, and provided a more detailed description of the vulnerability.
Initial creation