Impact
A missing authorization flaw in Google Chrome’s browser allows a remote attacker to bypass system access restrictions by serving a crafted HTML page. The vulnerability is a classic example of improper authorization (CWE‑862) and can lead to unauthorized control over system resources if exploited.
Affected Systems
The issue affects all Chrome desktop releases prior to version 153.0.8010.36, regardless of operating system or build. Users running these versions are susceptible until they upgrade to a patched build.
Risk and Exploitability
The CVSS score is 4.3, EPSS score < 1%, and the vulnerability is not listed in the CISA KEV catalog. The Chromium project rates the severity as Medium. The attack vector is inferred to be remote – a malicious web page can be served to the victim’s browser, allowing the attacker to elevate privileges by tricking the user into loading the content.
OpenCVE Enrichment
Debian DLA
Debian DSA