Impact
Google Chrome versions prior to 153.0.8010.36 contain a CORS authorization flaw (CWE‑862) that allows an attacker who has gained control of the renderer process to craft a malicious web page that bypasses the browser’s same‑origin policy. This flaw would give the attacker the ability to read or manipulate the content of any origin that the vulnerable user has accessed, potentially leaking confidential data or injecting malicious content.
Affected Systems
Users running Google Chrome before version 153.0.8010.36 are impacted. The vulnerability applies to all platforms supported by Chrome that use the affected renderer component.
Risk and Exploitability
The vulnerability is classified with medium severity by Chromium security. Exploitation requires an attacker to already have compromised the renderer process, which is a non‑trivial precondition but not impossible in compromised or malicious environments. The CVSS score is 3.1 and the EPSS score is below 1 %, and the vulnerability is not listed in CISA KEV. If the precondition is satisfied, the attacker can bypass the browser’s origin enforcement, enabling data exfiltration or malicious code injection across sites.
OpenCVE Enrichment
Debian DLA
Debian DSA