Impact
A race condition in the Core component of Google Chrome for Windows, present before version 152.0.7977.65, permits a remote attacker who successfully lures a user into opening a specially crafted HTML page to bypass the browser’s web origin policy. This can potentially allow the attacker to read or manipulate data that is normally restricted to a specific web origin, undermining the browser’s same‑origin security model. The vulnerability is classified with a low security severity by the Chromium team, yet it represents a tangible threat to the confidentiality and integrity of user data exposed to malicious web content.
Affected Systems
All users running Google Chrome on Windows with a browser version earlier than 152.0.7977.65 are at risk. The flaw originates from Chrome’s core code and is specific to the Windows build of the browser.
Risk and Exploitability
The EPSS score is less than 1%, and it is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been documented. The CVSS score of 4.3 signifies a low severity. Although the flaw permits a remote exploitation path—requiring the user to open a maliciously crafted page—the lack of known exploits and the low severity rating suggest a low likelihood of active exploitation. Nevertheless, the potential to bypass the origin policy warrants a timely patch to eliminate the race condition and protect sensitive data.
OpenCVE Enrichment
Debian DLA
Debian DSA