Impact
The vulnerability arises from incorrect authorization in Chrome’s navigation handling, allowing a crafted web page to bypass the browser’s web origin policy. This flaw can enable an attacker to read or modify data across origins, undermining confidentiality and integrity of the user’s browsing session. It is identified as a CWE‑863 flaw; the description does not detail the exact mechanics, so it is inferred that the error occurs during navigation events where the browser accepts cross‑origin transitions.
Affected Systems
Affected are all Google Chrome browsers on any supported operating system running a version earlier than 152.0.7977.65. The flaw exists in the stable channel and is mitigated by the latest update.
Risk and Exploitability
The CVSS score of 4.3 and an EPSS of less than 1% indicate moderate risk and low exploitation likelihood. No CISA KEV listing means no known public exploit. The attack vector would require the victim to open a malicious HTML page or visit a compromised site, which suggests that social engineering or phishing is the most feasible delivery method.
OpenCVE Enrichment
Debian DLA
Debian DSA