Impact
The flaw is an incorrect authorization in the Select HTML element in Google Chrome prior to 152.0.7977.65. An attacker using a crafted web page can circumvent the browser’s same‑origin restriction, potentially exposing or altering data from other origins. Chromium rates the vulnerability as low severity.
Affected Systems
The issue affects all users running Google Chrome versions older than 152.0.7977.65. Based on the update link, the affected channel appears to be the desktop stable channel, but the precise platform coverage is not detailed in the report, so all desktop stable channel builds are likely targeted.
Risk and Exploitability
Exploitability is relatively straightforward; an attacker merely needs to host a malicious page that contains the vulnerable Select element. No public exploit is listed, and the EPSS score is < 1%, but the ability to bypass the origin policy is a clear threat to confidentiality and data integrity. Prompt mitigation is advised despite a CVSS score of 4.3 indicating low severity.
OpenCVE Enrichment
Debian DLA
Debian DSA