Impact
An incorrect authorization check in Chrome's WebProtect component allowed a remote attacker to trigger a crafted HTML page that could read or leak confidential data that should not be disclosed. The weakness is a flaw in the access control logic (CWE-863), enabling the attacker to bypass normal permissions and gain unauthorized data access.
Affected Systems
Google Chrome browsers running any version before 152.0.7977.65 are impacted, including any distribution that has not applied the 152.0.7977.65 or later updates. The vulnerability exists in the WebProtect module that is part of the stable channel build.
Risk and Exploitability
The EPSS score of <1%, and the CVSS score of 6.5 indicates a medium impact assessment. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is a remote attacker delivering a malicious HTML page through a website or email attachment, which exploits the deficient authorization control. While no public exploits have been reported, the medium severity rating suggests a moderate risk to confidentiality if the browser misleads a user into visiting the crafted page.
OpenCVE Enrichment
Debian DLA
Debian DSA