Impact
This vulnerability arises from a missing authorization check in Google Chrome on macOS. A remote attacker can bypass the browser's web origin policy by delivering a specially crafted HTML page that reaches a privileged internal page, allowing the attacker to read or manipulate data that should be restricted. The flaw therefore enables unauthorized privileged page access, potentially exposing sensitive user information and setting the stage for more advanced exploitation if successful.
Affected Systems
Users running the stable channel of Google Chrome on macOS prior to version 152.0.7977.65 are affected. The issue is limited to desktop Chrome on macOS; earlier releases, beta or other platform versions are not impacted.
Risk and Exploitability
The exploit requires the victim to open a malicious HTML file or page, so user interaction is mandatory. No public exploit code is available, and the EPSS score is less than 1%. The CVSS score of 4.3 indicates moderate risk, and the vulnerability is not listed in the CISA KEV catalog. Although the direct impact is restricted to a single user session, the ability to access privileged pages could serve as a foothold for subsequent attacks if an attacker successfully deceives a user.
OpenCVE Enrichment
Debian DLA
Debian DSA