Impact
The defect is an incorrect authorization logic within the Edit functionality of Google Chrome. A malicious web page that runs in the browser can trick the system, leading to the exposure of sensitive data that should be protected. This flaw belongs to the authorization weakness class CWE‑863 and can result in information disclosure when the attacker invokes the Edit feature.
Affected Systems
Clients affected are users running any Google Chrome installation dated before 152.0.7977.65. This includes desktop versions on all supported operating systems. The vulnerability is bound to the browser component and does not involve native code or external plugins.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score is under 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the victim to load a specially crafted HTML document, often through a normal browsing session. Because the flaw resides in browser code, exploitation is possible remotely without additional credentials.
OpenCVE Enrichment
Debian DLA
Debian DSA