Impact
This flaw occurs in Google Chrome's network stack, where an incorrect authorization check allows a crafted HTML page to gain privileged access to system resources normally protected by the browser. When a user opens such a page, the browser may treat the content as if it has higher privileges, enabling the attacker to read or modify restricted data. The vulnerability is rated medium with a CVSS score of 4.3 and relates to CWE‑863 (Authorization Bypass through User-Controlled Input).
Affected Systems
Google Chrome desktop builds older than 152.0.7977.65 are affected. The issue resides in the network stack that validates user privileges during web content rendering, meaning any user running a vulnerable Chrome version on a desktop machine may be compromised if they visit a malicious HTML page.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation in the wild. With a CVSS score of 4.3, the flaw is considered medium severity. The likely attack vector is remote: the attacker must host a crafted HTML page and entice a victim to open it, which triggers the bypass during rendering.
OpenCVE Enrichment
Debian DLA
Debian DSA