Impact
A cross‑site request forgery flaw in Chrome’s DeviceBoundSessionCredentials allows a remote attacker to bypass the browser’s web origin policy through a crafted HTML page. The vulnerability could enable malicious sites to access or manipulate resources that should be restricted by same‑origin rules, potentially leading to credential theft or data exfiltration. The reported severity is Medium.
Affected Systems
Google Chrome desktop builds older than 153.0.8010.36 on all supported operating systems are affected. Users running these versions should be aware of the risk.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the Medium severity range. The EPSS score of less than 1% indicates a very low exploitation probability, and the flaw is not listed in the CISA KEV catalog, pointing to limited public exploitation data. Exploitation would still require a user to open a maliciously crafted page in Chrome, making the attack vector user‑dependent. The absence of publicly disclosed exploits suggests a lower immediate risk, but the flaw remains actionable if an attacker can entice a user to visit a malicious site.
OpenCVE Enrichment
Debian DLA
Debian DSA