Impact
An incorrect authorization check in Chrome extensions before version 152.0.7977.65 lets a remote attacker who has already compromised the renderer process bypass the web origin policy using a specially crafted HTML page. The flaw means that malicious content can be served as though it came from a trusted origin, potentially allowing data theft or other unauthorized actions. The identified weakness maps to CWE‑863, reflecting a failure of returned authorization decisions to meet required security controls.
Affected Systems
Google Chrome products running any build prior to 152.0.7977.65 are affected, including desktop releases on Windows, macOS, and Linux where extensions can be installed from third‑party sources. Users on older stable channel releases remain vulnerable if they have not applied the latest security update.
Risk and Exploitability
The CVSS score is 4.3, indicating low severity, and the EPSS score is < 1%, suggesting a low likelihood of exploitation. However, the vulnerability requires that the attacker already control the renderer process, which could be achieved through exploitation of another weakness or malicious extensions. In the absence of a CISA KEV listing, there is no known widespread exploitation reports, but the flaw’s impact on cross‑origin data privacy warrants prompt mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA