Impact
Information leakage in Chrome core exposed cross‑origin data when a user installed a specially crafted extension. The flaw lets a remote attacker read data that should be protected by the same‑origin policy, potentially revealing sensitive information such as cookies, local storage, or other browser secrets.
Affected Systems
Google Chrome on all platforms – versions earlier than 153.0.8010.36. The advisory lists the affected build numbers for Windows, macOS, Linux, Android and iOS.
Risk and Exploitability
CWE‑200 indicates an information‑disclosure weakness. The likely attack vector is a social‑engineering scenario where a malicious extension is installed by a user. No public exploits are documented, the EPSS score is < 1%, and the CVSS score is 4.3; the flaw is not listed in CISA’s KEV catalogue. The Chromium security team rated the issue as Low, suggesting a moderate overall risk given the requirement to install the compromised extension, but the path to exploitation is straightforward once the extension is present. No additional privileges or system‑level vulnerabilities are needed to gain the disclosed data.
OpenCVE Enrichment
Debian DLA
Debian DSA