Impact
The WebProtect component in Google Chrome has an incorrect authorization check that allows an attacker to disclose sensitive information by loading a specially crafted HTML page. This flaw represents a missing or flawed access control and is classified as an authorization weakness (CWE-863).
Affected Systems
All builds of Google Chrome prior to version 152.0.7977.65 are affected. Any installation of Chrome that does not include the update delivered by’s stable-channel does not contain the fix.
Risk and Exploitability
The probable attack vector is a remote HTML page served by an attacker that a victim must view or load in Chrome. Because the flaw does not require elevated privileges on the victim’s system, exploitation is straightforward for a user who encounters the malicious page. The CVSS score of 6.5 indicates medium severity, the EPSS score is below 1 %, and the issue is not listed in CISA’s KEV catalog, suggesting a moderate risk with no widespread exploitation reported yet.
OpenCVE Enrichment
Debian DLA
Debian DSA