Impact
Improper input validation in ReaderMode allows a remote attacker to bypass the web origin policy and access a privileged page through a crafted HTML page. The flaw could enable the attacker to execute privileged actions in the context of that page. The vulnerability is based on CWE-20 and is classified as low severity by Chromium security teams.
Affected Systems
Google Chrome browsers with versions earlier than 152.0.7977.65 are affected. The ReaderMode feature is the specific component impacted.
Risk and Exploitability
The CVSS score is not disclosed, the EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. The attack requires a social‑engineering vector where the user opens or interacts with a malicious HTML page that triggers ReaderMode. Once the page is loaded, the origin policy is bypassed, allowing the attacker to access privileged resources within that context.
OpenCVE Enrichment