Impact
A missing authorization check in DevTools of Google Chrome prior to 152.0.7977.65 enables a remote attacker to obtain sensitive information through UI interaction. The vulnerability is classified as medium severity and allows only data disclosure, not execution or denial of service. It requires the attacker to convince a user to interact with the DevTools interface, typically through social engineering.
Affected Systems
The affected product is Google Chrome. Any Chrome installation older than version 152.0.7977.65 is vulnerable. No other vendors or products are listed.
Risk and Exploitability
The EPSS score is <1%, indicating a very low likelihood that this vulnerability is actively exploited in the wild. The CVSS score of 6.5 classifies it as Medium severity. It is not listed in the CISA KEV catalog, so no confirmed public exploitation is known. However, the lack of authorization in DevTools means that an attacker who successfully socially engineers a user can gather confidential information from the browser’s context. The risk is moderate, primarily tied to user interaction and potentially widespread in environments where sensitive data is rendered in Chrome. Prompt mitigation is advised to reduce the attack surface.
OpenCVE Enrichment
Debian DLA
Debian DSA