Impact
Improper input validation in the Network component of Google Chrome allowed a remote attacker to bypass the web origin policy by serving a crafted HTML page. This flaw lets malicious content from one origin interact with resources or data belonging to another origin without the same‑origin restrictions, potentially exposing sensitive information or enabling further attacks. The weakness corresponds to CWE‑20, Input Validation.
Affected Systems
Google Chrome browsers. Versions prior to 153.0.8010.36 are affected. Any installation of Chrome that is older than the stable‑channel update released in September 2026 is vulnerable.
Risk and Exploitability
Chromium indicates a medium severity for this vulnerability. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate but unquantified risk. The CVSS score of 4.3 indicates a moderate severity. The attack likely requires a remote attacker to deliver a malicious HTML document to a victim’s browser; thus the vector is a network‑based, web page delivery. The entry provides no evidence of elevated privileges or code execution, but the breach of origin policy could lead to data exfiltration or unauthorized actions on behalf of the user.
OpenCVE Enrichment
Debian DLA
Debian DSA