Impact
The vulnerability is an improper input validation flaw in DeviceBoundSessionCredentials in Google Chrome. It enables a remote attacker who leverages social engineering to craft network traffic that bypasses the browser’s web origin policy. The flaw is associated with CWE‑20, which describes input validation failures that can lead to unauthorized security behavior.
Affected Systems
Affected products are Google Chrome browsers prior to version 152.0.7977.65 on all platforms. Users running any of the older Chrome releases are at risk. The issue was acknowledged in the Chromium issue tracker and addressed in the 152.0.7977.65 update.
Risk and Exploitability
The EPSS score is very low, below 1%, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 4.3 indicates low overall severity. The official severity assigned by Chromium is Low. However, because the flaw permits a remote attacker to bypass the web origin policy through crafted traffic, successful exploitation could potentially expose domain‑scoped web content or interact with device‑bound session credentials in ways not originally permitted. An attacker would need to convince a user to download or access malicious content to trigger the crafted traffic, making the threat primarily associated with social engineering.
OpenCVE Enrichment
Debian DLA
Debian DSA