Impact
An incorrect authorization check in the Document Object Model layer of Google Chrome allows a remote attacker to craft a malicious HTML page capable of reading private data that the browser should protect. The flaw concerns the use of user-controlled values as authorization keys and is formally identified as CWE-863. No privilege escalation or code execution can be achieved; the primary consequence is the disclosure of confidential information to the attacker.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability, and the EPSS score of <1% suggests this exploit is unlikely to be seen in the wild at present. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploitation. In order to exploit the flaw, a victim must visit a specially crafted HTML page. The necessary delivery method is inferred – the malicious page may be hosted on the web, embedded in an email attachment, or stored locally – as the vulnerability is triggered when the browser parses a DOM constructed from untrusted input. Attackers can therefore target any user who opens a malicious page or file containing the vulnerable DOM references.
OpenCVE Enrichment
Debian DLA
Debian DSA