Impact
Google Chrome versions prior to 152.0.7977.65 on Windows store notification payloads with insufficient encryption strength. An attacker can exploit this weakness by hosting a crafted HTML page that, through social engineering, tricks a user into interacting with a notification. The crafted content then bypasses the browser’s web origin policy, allowing the attacker to read or manipulate data across origin boundaries. The vulnerability is classified as Medium severity by Chromium’s internal scoring system.
Affected Systems
Any Windows user running Google Chrome before version 152.0.7977.65 is affected. The issue specifically targets the notification subsystem of the Chrome browser.
Risk and Exploitability
The risk is elevated by the remote nature of the exploit and the reliance on user interaction, which is common in social engineering attacks. An EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low probability of exploitation, yet the vulnerability’s CVSS score of 4.3 places it in the Medium severity range, indicating that users who have not updated their browsers remain at risk. An attacker would likely deliver malicious HTML via email or a phishing site, and the lack of robust encryption in the notification channel removes a key defense against cross-origin data leakage.
OpenCVE Enrichment
Debian DLA
Debian DSA