Impact
Chrome WebUI lacks proper authorization checks in versions prior to 153.0.8010.36, permitting a compromised renderer process to use a crafted HTML page to bypass the browser’s same‑origin policy. This flaw can let an attacker read or modify data belonging to other web origins, potentially exposing sensitive user information or executing arbitrary code within the browser sandbox.
Affected Systems
All Google Chrome releases older than 153.0.8010.36 are affected, including stable channel builds on desktop platforms. The vulnerability is specific to the Chrome WebUI and its renderer processes.
Risk and Exploitability
The flaw has a CVSS score of 3.1, indicating low severity. The EPSS score is <1%, suggesting a very low exploitation probability. It is not listed in the CISA KEV catalog. An attacker would need to compromise a renderer process and deliver a malicious HTML page, implying a remote exploitation scenario that requires prior foothold or social engineering. Given the low severity and very low exploitation probability, monitoring is appropriate but patching is still advisable.
OpenCVE Enrichment
Debian DLA
Debian DSA