Impact
The vulnerability arises from an improper state validation step in Chrome’s Safe Browsing module. A remote attacker can craft a malicious HTML page that exploits this flaw to bypass system access restrictions enforced by Safe Browsing, enabling unauthorized control over the affected system. This flaw falls under CWE‑754 and represents a weakness in access control that can breach system integrity.
Affected Systems
The flaw affects Google Chrome browsers before version 153.0.8010.36. All desktop builds within this version range are vulnerable until updated to the newer stable channel release.
Risk and Exploitability
The CVE lists a medium severity with a CVSS score of 6.5, and the EPSS score is below 1%, indicating a low probability of exploitation. It is not in the CISA KEV catalog, meaning there is no confirmed exploitation yet. The most likely attack vector is a crafted HTML page delivered to the victim’s browser, requiring no authentication or elevated privileges beyond the user’s Chrome session.
OpenCVE Enrichment
Debian DLA
Debian DSA