Impact
The vulnerability is a missing authorization check in the BrowserTag feature of Google Chrome. A remote attacker can craft a malicious Chrome extension that, if a user installs it through social engineering, can read sensitive information that should be protected. The flaw is a CWE-862, missing authorization.
Affected Systems
The issue affects all installations of Google Chrome versions older than 152.0.7977.65. Google provides a patch with the 152.0.7977.65 stable channel update, and any older Chrome versions remain vulnerable.
Risk and Exploitability
The feature allows data disclosure but does not provide remote code execution. The EPSS score is reported as < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates a medium severity level. Attackers must first deceive users into installing a malicious extension, so the likelihood of exploitation depends on social engineering skill. Nevertheless, the flaw is categorized with low severity, yet still poses a risk of sensitive data leakage.
OpenCVE Enrichment
Debian DLA
Debian DSA