Impact
The vulnerability is an incorrect authorization condition in the Loader component of Google Chrome that allows a malicious HTML page to be specially crafted so that a remote attacker can gain system access privileges. The flaw is classified as CWE‑863, which is an authorization Bypass. It does not directly expose code execution but enables the attacker to perform privileged operations normally blocked by the operating system through the browser’s privileged context.
Affected Systems
All operating systems that install Google Chrome before version 153.0.8010.36 are affected, regardless of platform, as the Loader component has been present across Chrome releases. The issue exists in every build of Chrome that predates the 153.0.8010.36 release.
Risk and Exploitability
While the Chromium security severity is listed as Low, the exploitation path requires social engineering to get a user to load a crafted HTML page. No EPSS score is available and the vulnerability is not represented in the CISA KEV catalog, suggesting that large‑scale exploitation is not currently documented. However, because the flaw allows a bypass of system access restrictions, it remains a concern for environments that allow untrusted web content or rely on Chrome for system administration tasks. The attack vector is inferred to be a crafted web page that the user would need to visit or otherwise trigger through a phishing or malicious link. The lack of public exploits and the social‑engineering requirement moderate the immediate risk to systems that enforce strict web filtering or user training.
OpenCVE Enrichment