Impact
This vulnerability allows a remote attacker who has already compromised the renderer process to forge an HTML page that bypasses Chrome’s web‑origin policy. The flaw is an improper authorization error in the Transactions Platform, enabling unauthorized access to resources that should be limited to the page’s. The impact is potential disclosure of sensitive data or manipulation of content from another origin. The flaw is classified by CWE‑863: Improper Authorization.
Affected Systems
Google Chrome browsers running versions earlier than 152.0.7977.65 on the desktop are affected. Applications using this version of the Transactions Platform are vulnerable until an update releases the remedy.
Risk and Exploitability
Because the attacker must already control the renderer process, the attack requires a prior compromise or a separate exploit that grants that level of access. The CVSS score is 4.3, although Chromium reports the severity as High. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating that there is no current evidence of widespread exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA