Impact
A flaw in Chrome's TabGroups handling allows an attacker to bypass an authorization check and read data that should be locked down, potentially exposing sensitive information. The weakness, classified as missing check for authorization, could be triggered by sending specially crafted network traffic to the browser, causing it to return protected data to the attacker. The vulnerability exists in all Chrome releases prior to 152.0.7977.65, as documented by Chromium, with a medium severity rating from the Chromium security teams.
Affected Systems
Google Chrome versions older than 152.0.7977.65 on any platform that uses the stable release channel.
Risk and Exploitability
The vulnerability can be exploited remotely through crafted network traffic, and the risk is considered medium as the CVSS score is 6.5. The EPSS score of less than 1% indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The known CWE-863 signals an authorization bypass, requiring the attacker to send the required traffic to a Chrome instance, making the threat moderate if the attacker can reach the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA