Impact
The vulnerability exists in the Chrome Network module where a missing authorization check allows a compromised renderer process to request network resources that bypass the browser’s same‑origin policy. This flaw is identified as CWE-862 and is rated Medium severity by Chromium security. By serving a specially crafted HTML page, an attacker can cause the renderer to access cross‑origin data, potentially exfiltrating confidential information or injecting malicious content.
Affected Systems
All installations of Google Chrome on desktop platforms running a stable‑channel version older than 152.0.7977.65 are affected. This includes Windows, macOS, and Linux environments, and the issue is not tied to any specific operating system.
Risk and Exploitability
The attack requires a prior compromise of the renderer process, so the privilege level of the attacker must be high; this inference is based on the description of the vulnerability. The CVSS score is 4.3 and the EPSS score is < 1%, indicating a Medium severity rating and suggesting a moderate risk. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are currently documented. Updating Chrome promptly is the recommended remediation to restore proper authorization checks and prevent the bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA