Impact
The vulnerability is a missing authorization flaw in the Actor component of Google Chrome, which permits an attacker to obtain sensitive information by viewing a crafted HTML page. The flaw is identified as CWE-862 and CWE-425, indicating insufficient authorization checks that allow unauthorized data access. Because the component deals with security-sensitive data, any memory or data exposed through this flaw could reveal private content to an adversary, undermining user confidentiality.
Affected Systems
Any installation of Google Chrome running a version earlier than 153.0.8010.36 is potentially vulnerable. Devices that have not applied the update containing the authorization fix are at risk of leaking sensitive data when browsing malicious or deceptively crafted web content.
Risk and Exploitability
The CVSS score of 6.5 marks the issue as medium severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The likely attack vector is a remote attacker delivering a malicious HTML page to the victim’s browser; based on the description, it is inferred that the attacker can entice the user to visit the crafted page, after which the missing authorization permits reading protected information. The vulnerability is not listed in CISA’s KEV catalog, but the medium severity combined with a remote attack surface suggests that timely remediation is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA