Impact
The vulnerability is an incorrect authorization check (CWE-863) in the WebUI of Google Chrome, affecting all versions prior to 153.0.8010.36. A remote attacker can serve a malicious HTML page that tricks the browser into loading a privileged internal page, thereby bypassing user‑level restrictions. This enables unauthorized access to configuration or management functions exposed through the WebUI, potentially compromising confidentiality or integrity on the compromised machine.
Affected Systems
Affected products are Google Chrome browsers operating whether on Windows, macOS, or Linux before version 153.0.8010.36. The issue exists in desktop builds where the WebUI is available. No other vendors or products are reported to be impacted by this CVE.
Risk and Exploitability
The flaw is classified as Medium severity within Chromium, with a CVSS score of 6.5 and an EPSS score of < 1%, indicating a low but non-zero likelihood of exploitation. The attack vector requires a malicious HTML page to be loaded by the target browser, so the attacker must have some way to serve or lure the victim to such content. The vulnerability is not listed in CISA’s KEV catalog, so there is no evidence of active exploitation. Nonetheless, the potential to gain privileged access makes remediation a high priority.
OpenCVE Enrichment
Debian DLA
Debian DSA