Impact
An incorrect authorization check in the Chrome Loader component allows a remote attacker to craft a malicious HTML page that bypasses the browser’s same‑origin policy. The flaw enables unauthorized access to resources that should be isolated by origin isolation, violating the integrity and confidentiality guarantees of web content.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. The issue applies to all builds of the stable channel that contain the vulnerable Loader implementation, regardless of platform or geographic location.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as Medium severity. The EPSS score is less than 1 %, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a crafted HTML page that a user must open in Chrome; this inference is drawn from the description. As a result, an attacker only needs to lure a user to view the malicious content to exploit the flaw. Updating Chrome to version 152.0.7977.65 or newer removes the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA