Impact
The vulnerability is an incorrect authorization mechanism in the extensions subsystem of Google Chrome, allowing a crafted extension to bypass system access restrictions. This flaw enables a malicious extension to perform privileged actions that standard Chrome extensions are not permitted to do, leading to possible escalation of privileges within the browsing session or the underlying operating system. The weakness is identified as CWE‑863, indicating a failure to enforce appropriate access controls, and is rated Medium security severity by Chromium.
Affected Systems
Google Chrome is affected, specifically all versions released prior to 153.0.8010.36. No further version details are provided; systems running Chrome earlier than this revision are at risk.
Risk and Exploitability
The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability has not been listed in CISA’s KEV catalog. With a CVSS score of 6.5, the flaw is considered medium severity, yet it permits a remote attacker to craft an extension that, once installed, can subvert Chrome’s permission model. In practice, successful exploitation would involve deceiving a user into installing a malicious extension or delivering it through a compromised extension store, after which the attacker could gain elevated privileges within the Chrome process or beyond. Therefore, the risk remains significant for users running the affected versions, and the vulnerability should be addressed promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA