Impact
Google Chrome’s Contacts feature contained a missing authorization check (CWE-862) that allowed a remote attacker who had already compromised the renderer process to read user contact data via a crafted HTML page. The vulnerability is triggered by social engineering; an attacker can lure a user into loading a malicious page that exploits the lack of access control to grant the attacker privileged access to contacts information. The impact is the disclosure of potentially sensitive personal data, representing a data‑exposure risk rather than code execution.
Affected Systems
The flaw exists in all Chrome releases before version 153.0.8010.36. Systems running any earlier Chrome stable channel are affected; versions 153.0.8010.36 and later include the fix.
Risk and Exploitability
The vulnerability has a low Chromium severity and a CVSS score of 5.3. The EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to gain renderer process privileges and deliver a crafted HTML page, typically through social engineering. Because the attacker must already compromise the renderer process and social engineer a user, the overall risk is moderate, but the data exposure potential warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA