Impact
The vulnerability in Google Chrome’s CORS implementation allows a remote attacker to craft network traffic that tricks the browser into trusting a certificate that does not belong to the intended origin, thereby bypassing the web origin policy. This flaw is an example of improper authentication or validation (CWE-295) and can lead to unauthorized access or manipulation of data that should be confined to a trusted domain.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are affected. Any installation of Chrome that has not yet been updated to the fixed release is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 and an EPSS score of less than 1% indicate a low intrinsic severity and a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, exploitation requires a social‑engineering component, such as persuading a user to visit a maliciously crafted site that employs a forged certificate. If successful, the attacker could compromise the confidentiality or integrity of cross‑origin resources but would not gain arbitrary system control. The overall risk is moderate, pending ongoing monitoring for attack activity.
OpenCVE Enrichment
Debian DLA
Debian DSA