Impact
Incorrect authorization in Chrome’s SafeBrowsing component can allow a remote attacker to bypass system access restrictions. The flaw permits the deployment of a crafted HTML page that, when viewed, enables the attacker to perform actions beyond the intended permission scope. This vulnerability presents a potential Privilege Escalation through Authorization Bypass, though it is classified as low severity by Chromium’s security team.
Affected Systems
Google Chrome versions before 153.0.8010.36 are affected. Any installations of Chrome prior to that release that still use the default SafeBrowsing configuration are vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation. It is not listed in CISA KEV. The attack likely requires social engineering to get a victim to load a malicious HTML page, implying that the attacker would need user interaction or access to a compromised web source. Given the moderate severity, the overall risk is modest, but the specific authorization bypass could be leveraged to elevate privileges within the system.
OpenCVE Enrichment
Debian DLA
Debian DSA