Impact
The vulnerability arises from an incorrect authorization check in the Cross‑Origin Resource Sharing (CORS) handling of Google Chrome versions earlier than 153.0.8010.36. A remote attacker who has already gained control of the renderer process can craft a malicious HTML page that tricks the browser into treating cross‑origin requests as legitimate. The result is a bypass of the web origin policy, enabling the attacker to read protected resources, execute privileged scripts, or exfiltrate data that should be confined to a single origin. This flaw is classified as a medium‑severity issue by Chromium security, reflecting its potential impact on confidentiality and integrity.
Affected Systems
The affected product is Google Chrome. All versions before 153.0.8010.36 are vulnerable, regardless of operating system. Users running a legacy or manually managed installation that has not yet updated to the 153.0.8010.36 release or later are susceptible.
Risk and Exploitability
An exploitable path requires an attacker to have already compromised the renderer process, which is a more advanced prerequisite than a typical remote attack. Because the flaw is a CORS logic error, exploitation is limited to web origins served by a compromised renderer. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. Nevertheless, once the renderer is compromised, the ability to bypass the same‑origin policy can lead to significant data leakage or scripting attacks. The CVSS score of 3.1 indicates a low severity, but the risk remains contingent on the existing compromise of the renderer process.
OpenCVE Enrichment
Debian DLA
Debian DSA