Impact
An incorrect authorization check in Chrome’s permission system for extensions allows a remote attacker, aided by social engineering, to install a crafted extension that can read sensitive information. The flaw resides in the way Chrome validates extension permissions, leading to a breach of confidentiality for data the user has authorized elsewhere. The vulnerability is classified as CWE‑863, reflecting an authorization failure due to improper checks.
Affected Systems
The issue affects all users of Google Chrome on the desktop platform running versions prior to 153.0.8010.36. Any user who has enabled or installed extensions on these affected versions is potentially at risk until the fix is applied.
Risk and Exploitability
The CVSS score of the vulnerability is 7.5, indicating medium severity according to Chromium. The EPSS score is <1%, and it is not currently listed in CISA’s KEV catalog, suggesting limited known exploitation. However, the exploitation path requires user interaction – the attacker must persuade a user to install a malicious extension. If social engineering succeeds, the attacker can read data that the user has authorized to extensions and exfiltrate it. Given the medium severity and requirement for social engineering, the overall risk is moderate but still important to mitigate promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA