Impact
A missing authorization check in the Omnibox component of Google Chrome allows a remote attacker who successfully social‑engineers a victim to bypass system access restrictions. By manipulating a crafted HTML page entered into the Omnibox, the attacker can trigger the browser to load a privileged page that the victim would normally be barred from visiting. This flaw, identified as CWE‑862, effectively grants the attacker elevated local privileges on the affected machine. The flaw is also mapped to CWE‑551, indicating unauthorized access to privileged resources.
Affected Systems
Google Chrome browsers prior to version 153.0.8010.36 are vulnerable. The fix is available in the stable channel update released on September 8, 2026.
Risk and Exploitability
Chromium classifies the vulnerability as Medium severity. Its CVSS score is 6.5. Exploitation requires victim interaction with a crafted page; a social‑engineering approach is needed. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog, indicating no publicly known widespread exploitation. The risk remains moderate, with impact limited to devices running the affected Chrome version and depending on user behavior.
OpenCVE Enrichment
Debian DLA
Debian DSA