Impact
Improper input validation in Chrome’s Omnibox allows a remote attacker to craft network traffic that can bypass the browser’s web origin policy. The flaw requires social engineering to lead the user to engage with the malicious traffic, potentially giving the attacker the ability to read or manipulate resources that should be restricted by same‑origin rules. The vulnerability is classified as high severity and is considered an input validation flaw.
Affected Systems
Google Chrome versions earlier than 152.0.7977.75 are affected. The issue is specific to the Omnibox component of the browser and does not extend to other Chrome features or browsers.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity flaw, and the EPSS score is below 1%, suggesting a low likelihood of exploitation. It is not listed in the CISA KEV catalog. Extrapolating from the description, exploitation would involve remote manipulation of Omnibox input through crafted traffic and relies on user interaction via social engineering. Given the low EPSS, the risk remains high until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA