Impact
Google Chrome prior to 152.0.7977.65 contains an incorrect authorization check in the Extensions module that allows a remote attacker who has compromised the renderer process to load a crafted HTML page and traverse the browser’s web origin policy. The CVSS score for this issue is 4.3, classifying the vulnerability as low severity. The flaw is classified under CWE-863, which involves improper authorization. If exploited, the attacker can read or modify data across different web origins, potentially exposing sensitive user information or manipulating web content.
Affected Systems
All users running Google Chrome on the stable channel with versions earlier than 152.0.7977.65 are affected. The vulnerability exists in the Extensions subsystem of the Chrome browser running on any platform supported by the stable release channel.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating low severity according to the standard scoring system. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation, and the issue is not listed in KEV. However, the flaw requires the attacker to compromise the renderer process, which may be achieved through local privilege escalation or malicious extensions. Once these prerogatives are achieved, the attacker can bypass the browser’s same‑origin policy, enabling cross‑origin data theft or injection. The lack of public exploitation data does not diminish the potential damage to users who run vulnerable versions.
OpenCVE Enrichment
Debian DLA
Debian DSA