Impact
A missing authorization check in Chrome’s LocalNetworkAccess feature allows an attacker who has already compromised the renderer process to bypass system access restrictions with a crafted HTML page. The flaw may enable an attacker to reach local network resources that should be protected, potentially leading to further compromise of the host or internal network assets. The vulnerability is categorized as Chromium severity Medium, reflecting limited impact if the attacker cannot gain renderer control, but significant risk if such control is achieved.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 are affected. The issue applies to all release channels using that codebase.
Risk and Exploitability
The EPSS score, currently reported as less than 1%, and the lack of listing in CISA KEV suggest limited exploitation activity to date. An attacker must first compromise the renderer process, typically by luring the user to malicious content, before leveraging a crafted HTML page to trigger the LocalNetworkAccess bypass. The CVSS score of 4.3 indicates a low‑to‑moderate severity; organizations should still monitor for renderer compromise events and apply mitigations promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA