Impact
An incorrect authorization check in the Web Authentication system of Google Chrome versions prior to 153.0.8010.36 allows a remote attacker to bypass the browser's same‑origin policy by using a crafted Chrome extension. The flaw is a CWE‑863 condition where the browser fails to restrict authentication requests to the intended origin, giving the extension access to data from websites the user visits. If exploited, an attacker could read, modify, or inject credentials and other sensitive data across origin boundaries.
Affected Systems
Based on the description, the affected product is Google Chrome on the stable channel before version 153.0.8010.36. The issue is fixed in Chrome 153.0.8010.36 and later, so any user running an earlier stable release is vulnerable.
Risk and Exploitability
The Chromium severity of this flaw is Low; the CVSS score is 4.3 and the EPSS score is <1%. Attackers must deliver a malicious extension to the user, implying a social‑engineering or malicious‑web‑store vector. The flaw is not listed in CISA's KEV catalog and no public exploits have been documented, so widespread exploitation likelihood is low. Nonetheless, the capability to bypass origin restrictions could be leveraged by motivated actors.
OpenCVE Enrichment
Debian DLA
Debian DSA