Impact
A missing authorization check within Chrome DevTools allows a maliciously crafted Chrome extension to read data from origins beyond the allowed scope. The vulnerability can lead to sensitive information being disclosed to the attacker’s extension code, effectively compromising data confidentiality. The weakness is an Authorization Bypass (CWE‑862).
Affected Systems
Google Chrome. All builds prior to 153.0.8010.36 are affected. Any user running an older Chrome version is vulnerable, regardless of operating system or device type.
Risk and Exploitability
The vulnerability is categorized as low severity, with a CVSS score of 4.3, and has no reported exploitation in the wild. EPSS is < 1%, indicating no current known exploit efforts, and the issue is not listed in the CISA KEV catalog. The most probable attack vector involves a malicious Chrome extension that the user installs or that is injected via a compromised website; the attacker would then hijack DevTools to read cross‑origin data. Without such a malicious extension, the risk is very limited.
OpenCVE Enrichment
Debian DLA
Debian DSA