Impact
An incorrect authorization check in the Document Object Model of Google Chrome before version 152.0.7977.65 allows a remote attacker to potentially leak sensitive information via a crafted HTML page. This flaw is considered low severity by Chromium’s own security assessment but could enable unauthorized data exposure if exploited.
Affected Systems
Google Chrome browsers running versions prior to 152.0.7977.65 are affected. The issue exists in any release of Chrome before the 152.0.7977.65 patch, regardless of operating system or extension configuration.
Risk and Exploitability
The exploit can be triggered remotely simply by delivering a malicious HTML document to a Chrome user. The CVSS score of 6.5 indicates moderate severity, and the EPSS score (<1%) indicates low probability of exploitation, so the exact likelihood of exploitation remains low. The vulnerability is not listed in CISA’s KEV catalog, suggesting that widely known exploits have not yet been reported. Because the flaw involves missing authorization in DOM handling, an attacker could read or manipulate data that should be restricted, but no full remote code execution is displayed in the current data.
OpenCVE Enrichment
Debian DLA
Debian DSA