Impact
The vulnerability is a missing authorization check in the Preload functionality of Google Chrome versions earlier than 152.0.7977.65. A remote attacker can use a crafted HTML page that the browser preloads to bypass the browser’s web origin policy, allowing the attacker to request or manipulate resources that are normally protected by the same-origin restriction. This flaw is classified as CWE-862.
Affected Systems
This issue affects Google Chrome browsers on desktop operating systems across any stable channel version prior to 152.0.7977.65. Versions from older stable, beta, or dev channels are also vulnerable if the patch has not yet been applied by automatic updates.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is less than 1 %, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to deliver a crafted HTML page that utilizes the preload feature, and the risk to a system is therefore moderate and can be mitigated by applying the official patch.
OpenCVE Enrichment
Debian DLA
Debian DSA