Impact
The vulnerability is a missing authorization check in the Chrome Extensions subsystem. A malicious extension crafted by an attacker can be installed by an unsuspecting user, and once installed it can read sensitive data such as browsing history, cookies, or other user data. The flaw allows an attacker to gain unauthorized access to private information, resulting in a full information disclosure against the user.
Affected Systems
Google Chrome browsers with a version older than 153.0.8010.36 are vulnerable.
Risk and Exploitability
The exploit requires the user to install a malicious extension. The severity is reported as medium by Chromium and is quantified with a CVSS score of 7.5, with an EPSS score of <1% that indicates a moderate to high risk but a low likelihood of exploitation. The vulnerability is considered exploitable primarily when users download extensions from untrusted or unofficial sources. As it is not listed in the CISA KEV catalog, there is currently no known active exploitation campaign against this CVE, although the EPSS score suggests that the chances of exploitation are low. The attack vector is remote via the extension installation mechanism.
OpenCVE Enrichment
Debian DLA
Debian DSA