Impact
A missing authorization check in Chrome’s Core component allows a remote attacker who has compromised the renderer process to serve a specially crafted HTML page that can modify the browser’s address bar. This flaw does not grant code execution or data theft but enables the page to display a fraudulent URL as though it were legitimate, thereby eroding user trust and facilitating phishing attacks. The weakness is classified as CWE‑862 (Missing Authorization) and CWE‑290 (Authorization Bypass Through User-Controlled Key).
Affected Systems
Any installation of Google Chrome prior to version 152.0.7977.65 is vulnerable. The Core component is part of the standard browser binary, so users of older releases on any operating system remain affected until the update is applied.
Risk and Exploitability
The exploit requires that the attacker first compromise or control a renderer process, which typically occurs through a prior vulnerability or a malicious web page. Based on the description, it is inferred that such a compromise could be achieved by embedding malicious content that triggers an existing flaw. The vulnerability relies on missing authorization (CWE‑862 and CWE‑290). The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates moderate severity, and while the risk to system integrity is limited, the threat to user confidence and potential for social engineering is significant.
OpenCVE Enrichment
Debian DLA
Debian DSA