Impact
The flaw in Google Chrome’s handling of certificate validation within the CORS mechanism allows a remote attacker to craft network traffic that deceives the browser into trusting a certificate that does not belong to the intended origin. This leads to a bypass of the web origin policy, granting the attacker the ability to access or manipulate data that should be confined to a trusted domain. The weakness is an instance of improper authentication or validation (CWE‑295).
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are affected. All installations of Chrome that have not yet been updated to the referenced fixed release are vulnerable.
Risk and Exploitability
The vulnerability has a low intrinsic severity rating and is not listed in the CISA KEV catalog, indicating a comparatively small exploitation footprint at present. The EPSS score is not available, so the probability of exploitation remains uncertain. Likely exploitation requires a social‑engineering component, such as persuading a user to load a maliciously crafted website that communicates with a forged certificate. Once executed, the attacker could compromise confidentiality or integrity of cross‑origin resources but would not gain arbitrary system control. The overall risk is therefore considered moderate, pending further monitoring for signifiers of attack activity.
OpenCVE Enrichment