Impact
Google Chrome versions prior to 153.0.8010.36 contain an improper encoding or escaping flaw in CSS output. This weakness permits a remote attacker, through a crafted HTML page, to bypass the web origin policy. Consequently, a malicious site could potentially read or modify data from other origins, leading to confidentiality and integrity violations for users.
Affected Systems
The vulnerability affects Google Chrome browsers running any version earlier than 153.0.8010.36. Updating to 153.0.8010.36 or later will remove the flaw. Users of earlier releases are susceptible.
Risk and Exploitability
The flaw is reported as medium severity with a CVSS score of 4.3; the EPSS score is <1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. The attacker would need a victim to load a specially crafted web page, meaning the vulnerability is exploitable through normal browsing. Although the exploitation path is straightforward, the modest CVSS score and low EPSS suggest that the risk is moderate but not negligible for users who frequently visit untrusted sites.
OpenCVE Enrichment
Debian DLA
Debian DSA