Impact
Improper input validation in the Variations module of Google Chrome allows a remote attacker to send crafted network traffic that can bypass the browser’s web origin policy. The flaw permits network requests that are treated as if they come from a different origin than intended, resulting in a violation of Chrome’s same‑origin enforcement.
Affected Systems
All users running Google Chrome versions older than 152.0.7977.65 on the stable channel are affected by this vulnerability.
Risk and Exploitability
The flaw can be exploited remotely by sending malformed traffic to Chrome’s Variations service. With a CVSS score of 4.3 the vulnerability is considered medium severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to target the Variations endpoint to trigger the policy bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA