Impact
This flaw occurs because Google Chrome versions prior to 153.0.8010.36 lack a critical authorization check. A malicious HTML page can cause the browser to treat content as if it had higher privileges, allowing the attacker to bypass access controls normally enforced by Chrome. The issue is mapped to CWE‑862, Missing Authorization Control, and is rated medium severity by Chromium. Based on the description, the attacker must deliver or embed a crafted page that the victim opens in Chrome to exploit the vulnerability.
Affected Systems
Any user running Google Chrome with a release earlier than 153.0.8010.36 on any supported desktop platform is vulnerable. No additional operating system or device restrictions are specified in the available data. The vulnerability affects the entire Chrome browsing session, not just individual tabs or extensions.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium impact. The EPSS score of less than 1% suggests a low current likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is a crafted HTML page delivered over the network; the attacker only needs the victim to open the page in Chrome. Successful exploitation would elevate the attacker’s privileges within the Chrome process, potentially allowing actions that exceed the browser’s intended authorization scope. Based on the description, it is inferred that the victim must voluntarily navigate to or load the malicious page.
OpenCVE Enrichment
Debian DLA
Debian DSA