Impact
Chrome’s Loader incorrectly resolves references in versions prior to 152.0.7977.65, allowing a remote attacker to craft network traffic that tricks the browser into treating a resource as same‑origin. The description indicates a bypass of the web origin policy; it is inferred that this could enable the attacker to access data or execute scripts within the victim’s origin context, though those specific outcomes are not explicitly documented.
Affected Systems
The vulnerability is present in Google Chrome desktop releases older than 152.0.7977.65 on all supported operating systems; no other vendors or products are listed as affected.
Risk and Exploitability
The EPSS score of less than 1 % and the fact that the vulnerability is not listed in CISA’s KEV catalog imply a low probability of active exploitation. The CVSS score of 4.3 classifies it as medium severity, indicating that the flaw can lead to a partial compromise of web origin integrity but does not enable broad remote code execution. Exploitation requires only crafted network traffic that tricks the Loader into resolving a reference as same‑origin, and does not depend on user interaction or local privilege escalation. Consequently, while an attacker might gain unauthorized access to resources marked as same‑origin, the overall impact is limited compared to high‑severity vulnerabilities. Prompt patching and monitoring of anomalous origin resolution attempts continue to be the primary defense.
OpenCVE Enrichment
Debian DLA
Debian DSA