Impact
A remote attacker can exploit a flaw in the Chrome extension system to read cross‑origin data by installing a malicious extension that the user believes is legitimate. The vulnerability is an Information Exposure weakness (CWE‑200) that allows the extension to bypass the browser’s normal same‑origin data restrictions.
Affected Systems
Google Chrome, available on all desktop platforms, is affected for versions earlier than 152.0.7977.65. The issue is reported to exist only before that release and has been addressed in later updates.
Risk and Exploitability
The flaw is exploitable only when a user installs a malicious extension, typically through social‑engineering techniques. No public exploit has been documented and the EPSS score is <1%, with a CVSS score of 6.5. The vulnerability is not listed in CISA KEV and is rated medium by Chromium, indicating a moderate confidentiality risk for users with vulnerable versions.
OpenCVE Enrichment
Debian DLA
Debian DSA