Impact
The flaw is an incorrect authorization check in Google Chrome’s Web Authentication flow, which is used for Passkeys and Security Keys. A remote attacker can craft an HTML page that, when loaded in the browser, bypasses Chrome’s same‑origin policy. This allows requests that appear to come from a trusted site, potentially accessing or altering data or credentials that the user would otherwise be protected against. The weakness is classified as CWE‑863, indicating an improper authorization failure.
Affected Systems
All desktop versions of Google Chrome prior to 152.0.7977.65 are affected. The stable channel release notes refer to the desktop stable channel, so mobile operating systems are not explicitly mentioned as impacted. Versions 152.0.7977.65 and newer contain the fix.
Risk and Exploitability
The vulnerability is triggered by visiting a malicious web page, representing a remote web‑origin attack vector. The EPSS score is <1%, indicating low risk of automated exploitation, and the flaw is not listed in the CISA KEV catalog. The CVSS score is 4.3, which is classified as Medium severity. Although the exploitation probability is low, bypassing the same‑origin policy poses a significant integrity and privacy risk by allowing forged requests from a compromised site. Until the issue is patched or mitigated, the best protection is to eliminate the vulnerability by updating or disabling the affected feature.
OpenCVE Enrichment
Debian DLA
Debian DSA