Impact
A flaw in Chrome’s DataTransfer component allows a remote attacker, once they have control over the renderer process, to bypass authorization checks and read sensitive data that should be protected. The vulnerability is classified as a medium severity flaw according to Chromium’s internal rating, and is associated with CWE‑863, which denotes improper authorization. The attacker can craft a malicious HTML page that triggers the vulnerable API, enabling unauthorized disclosure of data that the renderer had access to. The CVSS score of 5.3 confirms the medium severity.
Affected Systems
Google Chrome is affected. Versions prior to 153.0.8010.36 contain the unpatched flaw. All users running those older releases are at risk until an update is applied.
Risk and Exploitability
The exploit requires the attacker to have already compromised the renderer process, which typically demands a separate local or remote code execution vector. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV. With a CVSS score of 5.3, the risk is significant for systems running affected Chrome versions but is limited by the need for renderer compromise. Upgrading to a patched version mitigates the risk fully.
OpenCVE Enrichment
Debian DLA
Debian DSA