Impact
Missing authorization in the Downloads feature of Google Chrome allows a remote attacker to create a malicious extension that bypasses system access restrictions, enabling unauthorized actions beyond normal user permissions. The flaw is an access control weakness (CWE-862).
Affected Systems
Google Chrome browsers prior to version 153.0.8010.36 are affected.
Risk and Exploitability
The vulnerability can be exploited remotely by delivering a crafted Chrome extension. While an EPSS score of < 1% is available and the vulnerability is not listed in the CISA KEV catalog, the medium severity rating from Chromium—corresponding to a CVSS score of 6.5—indicates a non‑trivial potential for exploitation. Attacks would likely depend on a user installing a malicious extension or the attacker convincing a user to grant elevated extension permissions. The availability of a low EPSS score does not negate the risk; organizations should consider the possibility of social engineering or supply‑chain attacks that could deploy such extensions.
OpenCVE Enrichment
Debian DLA
Debian DSA