Impact
The vulnerability resides in the ControlledFrame component of Google Chrome, where an authorization check is missing. When a user visits a specially crafted HTML page, the browser can bypass the operating system’s access controls. This gives an attacker the ability to read or execute files outside the sandbox, compromising confidentiality and integrity of the system. The weakness is identified as CWE‑862, Missing Authorization, and the advisory rates the issue as Medium severity.
Affected Systems
Google Chrome browsers prior to build 153.0.8010.36, installed on any operating system that supports this version of Chrome. The affected builds are part of the stable channel for desktop. In effect, any user running a Chrome version older than 153.0.8010.36 is vulnerable.
Risk and Exploitability
The vulnerability can be exploited through a remote attack vector. An attacker needs to entice a user to load a malicious web page, which can be done via social engineering or compromised websites. Once the page loads, the browser’s missing authorization allows bypassing of system access restrictions, exposing sensitive files or data. The CVSS base score is 6.5, the EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits as of this analysis. Nevertheless, the attack requires only a simple crafted page and social engineering, making it relatively easy to attempt.
OpenCVE Enrichment
Debian DLA
Debian DSA