Impact
Chromium lacked proper cleanup of temporary UI components during the rendering lifecycle, allowing a remote attacker to craft a malicious Chrome extension that bypasses the browser’s same‑origin policy. This weakness could enable an attacker to read or modify JavaScript context and data normally restricted by origin boundaries. The vulnerability is identified as CWE‑459 – Incomplete Cleanup of Resource.
Affected Systems
All users of Google Chrome editions built prior to version 152.0.7977.65 are potentially affected. The issue is tied to the Chromium component that Chrome bundles, so any instance derived from that source code before the patch is vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known exploitation at this time. The vulnerability’s low severity rating in Chromium’s own assessment indicates that exploitation requires a targeted, social‑engineering attack; the attacker must convince a user to install a crafted extension. If successful, the attacker could obtain arbitrary access to data and scripts from the user’s browsing sessions.
OpenCVE Enrichment