Impact
An incorrect authorization check in the Loader component of Google Chrome allows a remote attacker to inject a crafted HTML page that can read or exfiltrate sensitive data from the browser. The vulnerability resides in Chrome’s handling of certain document types and manifests as privileged access where only authorized pages should be permitted. Consequently, an attacker could potentially read user data or credentials that the browser holds, leading to privacy and compliance violations. This weakness is classified as CWE-863, indicating improper authorization that can be exploited without privileged user interaction, and it also represents a CWE-551 access control flaw.
Affected Systems
Google Chrome users running versions prior to 153.0.8010.36 are affected. All desktop installations of the Chrome browser from earlier releases are vulnerable until the update that resolves the authorization flaw is applied.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is through a crafted HTML page delivered via a remote server or local file that the user is tricked into opening. While exploitation might not be trivial, the absence of mitigation in earlier versions means a successful attack would directly expose sensitive information to a remote adversary.
OpenCVE Enrichment
Debian DLA
Debian DSA