Impact
The vulnerability is an incorrect authorization check in Chrome extensions that allows a remote attacker, once they have compromised the renderer process, to bypass the browser’s web origin policy and load a privileged page. This flaw can lead to unauthorized access to sensitive browser data or functionality provided by privileged pages, and is categorized as CWE-863. The CVE description does not state code execution beyond this privilege escalation within the browser context.
Affected Systems
Google Chrome desktop versions older than 152.0.7977.65 on the stable channel are affected. The flaw resides in the renderer that handles extensions, so all systems running these versions with any installed extensions are potentially vulnerable if a renderer compromise is achieved.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity, and the EPSS score is less than 1%, indicating a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires a prior compromise of the renderer, which could be achieved via other vulnerabilities or malicious extensions. Because the attack path is indirect and the likelihood is low, the risk is moderate, but timely patching is advised.
OpenCVE Enrichment
Debian DLA
Debian DSA