Impact
Missing authorization in the Back‑Forward Cache allows a remote attacker who has already compromised the renderer process to execute a crafted HTML page that bypasses system access restrictions. The flaw removes the expected authorization checks, enabling the attacker to elevate privileges and access protected resources within the user’s environment.
Affected Systems
Google Chrome browsers prior to version 152.0.7977.65. Any user running an affected Chrome build is susceptible until an update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. Exploitation requires initial compromise of the renderer process, so it is not trivially exploitable from a remote standpoint. The EPSS score is less than 1% and the flaw is not listed in the CISA KEV catalog, indicating the overall risk is moderate pending update.
OpenCVE Enrichment
Debian DLA
Debian DSA