Impact
The flaw arises from incomplete cleanup in Google Chrome’s Browser before version 153.0.8010.36, allowing a remote attacker to craft a malicious extension that, once installed, bypasses the browser’s web origin policy. This access control weakness (CWE-459) could expose site‑specific data to malicious code and is rated Medium severity by Chromium.
Affected Systems
Google Chrome versions older than 153.0.8010.36 are affected. The issue was patched in the stable channel update released on 2026‑09‑08 and is documented in the Chromium issue tracker.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% reflects a very low probability of exploitation. Attackers would likely rely on social engineering to get a user to install a malicious extension that leverages the cleanup bug, potentially allowing read or modification of data from sites the user visits. The vulnerability is not listed in CISA’s KEV catalog, but success would compromise site‑specific confidentiality, integrity, or availability.
OpenCVE Enrichment
Debian DLA
Debian DSA