Impact
Improper input validation in Chrome’s Omnibox allows a remote attacker to craft network traffic that can bypass the browser’s web origin policy. The flaw requires social engineering to lead the user to engage with the malicious traffic, potentially giving the attacker the ability to read or manipulate resources that should be restricted by same‑origin rules. The vulnerability is classified as high severity and is considered an input validation flaw.
Affected Systems
Google Chrome versions earlier than 152.0.7977.75 are affected. The issue is specific to the Omnibox component of the browser and does not extend to other Chrome features or browsers.
Risk and Exploitability
The CVSS score is not provided, but the bug is labeled high severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Extrapolating from the description, exploitation would involve remote manipulation of Omnibox input through crafted traffic and relies on user interaction via social engineering. Given the lack of available probability metrics, the risk remains high until the patch is applied.
OpenCVE Enrichment