Impact
The flaw is an incorrect authorization mechanism in Chrome Controls that allows a remote attacker to create a crafted HTML page and bypass Chrome’s same‑origin policy. By exploiting this, an attacker can read or write data across origins, leaking confidential information or injecting malicious content into contexts that should be protected. The weakness is classified as CWE‑863: Improper Authorization.
Affected Systems
All installations of Google Chrome that have not yet upgraded to version 152.0.7977.65 are affected, regardless of platform. The CVE data does not specify which operating systems or build channels (e.g., Stable, Beta) are impacted, so affected systems are inferred to include any Chrome build that contains the vulnerable Controls feature prior to the announced patch.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity vulnerability, and the EPSS score of < 1 % signals a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. According to the CVE description, exploitation would require a malicious web page that lures a user to visit it. Once a user loads the crafted page, the attacker can execute cross‑origin requests that are normally blocked, enabling data theft or injection. The CVE data does not mention any documented exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA