Impact
Chrome Tabs contains an injection flaw that lets a remote attacker craft an HTML page to trick the browser into bypassing system access restrictions. The vulnerability enables the attacker to potentially execute browser‑level commands with elevated privileges, which could then be used to read or modify protected data or APIs on the host. The Chromium severity for this issue is rated medium.
Affected Systems
Users running Google Chrome version prior to 152.0.7977.65 on any platform are affected. No other vendors or product versions are listed as vulnerable.
Risk and Exploitability
While the EPSS score is < 1% and the issue is not in the CISA KEV catalog, the flaw is a typical browser injection (CWE‑74). An attacker must supply a malicious webpage to a user’s browser, so exploitation relies on user interaction or a tricked user. The vulnerability has a CVSS score of 4.3, a medium Chromium severity, and lack of known widespread exploitation suggest a moderate risk, but the potential for privilege escalation warrants prompt attention.
OpenCVE Enrichment
Debian DLA
Debian DSA