Impact
Google Chrome contains a CWE‑20 input validation weakness in its extension handling. The flaw allows a remote attacker to send specifically crafted network traffic to the browser, bypassing its built‑in web origin policy and causing the browser to load a privileged page that would normally be restricted. Based on the description, it is inferred that this could potentially enable an attacker to steal data or modify content in ways that break the same‑origin security model. According to Chromium, the security severity is Low.
Affected Systems
All desktop installations of Google Chrome that used a version earlier than 153.0.8010.36 are affected. The vulnerability exists in the core browser code that processes extension‑generated network requests. Based on the description, it is inferred that this issue would affect Windows, macOS, and Linux platforms.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity in the Chromium security database, and the EPSS score is reported as less than 1%, with no listing in the CISA KEV catalog. The attack vector is remote and only requires the attacker to send crafted traffic to a Chrome instance that has the vulnerable extension enabled. Based on the description, it is inferred that the vulnerability permits a web origin policy bypass which could allow data theft or unauthorized content manipulation, but it does not grant arbitrary code execution. The risk remains non‑trivial until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA