Impact
Chrome’s Sensor component has an authorization flaw that permits a remote attacker who has already compromised the renderer process to retrieve sensitive information by serving a specifically crafted HTML page. The vulnerability is classified as Medium severity by Chromium and maps to CWE-862, which concerns missing authorization.
Affected Systems
Google Chrome browsers running any version earlier than 152.0.7977.65 are affected; all later releases incorporate the fix.
Risk and Exploitability
The attack vector requires the attacker to already control the renderer process, meaning that the vulnerability is only exploitable after a prior compromise of the rendering environment. The CVSS score of 5.3 classifies the flaw as a Medium severity issue. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw allows data disclosure rather than system compromise, the overall risk is moderate, but the availability of a patch makes timely remediation important.
OpenCVE Enrichment
Debian DLA
Debian DSA