Impact
A flaw in the handling of stored passwords in Google Chrome before version 152.0.7977.65 allows an attacker who has already compromised the renderer process to trick the browser into bypassing its web origin policy by using a specially crafted HTML page. The missing authorization check permits the attacker to access or manipulate password data outside the intended scope, potentially exposing credentials or enabling further compromise. The vulnerability is classified as high severity and is related to the CWE-862 "Authorization Bypass Through User-Controlled Key."
Affected Systems
Version 152.0.7977.65 and earlier of Google Chrome on all supported operating systems are affected. No specific hardware or platform restrictions are noted; the vulnerability is tied to the Chrome renderer component.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate severity, and its EPSS score of <1% indicates a very low likelihood of exploitation. The KEV status shows it is not listed, and no publicly known exploits are available. The likely attack vector is remote exploitation through a crafted web page served to a user who has already compromised the renderer process. Once the renderer is controlled, the attacker can bypass the web origin policy and interact with stored passwords, leading to credential leakage or further lateral movement.
OpenCVE Enrichment
Debian DLA
Debian DSA