Impact
The vulnerability arises from incorrect authorization checks in the Omnibox component of Google Chrome before version 153.0.8010.36. A remote attacker can craft a malicious HTML page that tricks the browser into navigating a privileged page, effectively bypassing system access restrictions. This allows the attacker to view or interact with pages that are normally confined to privileged users, impacting confidentiality and integrity of protected information. The weakness corresponds to CWE‑863.
Affected Systems
Google Chrome browsers with versions earlier than 153.0.8010.36 are affected. Clients using older stable channel releases that have not yet received the 153.0.8010.36 update are at risk.
Risk and Exploitability
Chromium rates the security severity as Medium (CVSS 6.5), and the EPSS score is less than 1%. The flaw can be triggered remotely through a crafted HTML page, implying that a threat actor can exploit it without local access. Since the CVE is not listed in CISA’s KEV catalog and no exploit code has been reported, the likelihood of exploitation remains uncertain. Nevertheless, because the flaw permits direct access to privileged content, it poses a substantial threat if an attacker gains control of a device running the vulnerable browser.
OpenCVE Enrichment
Debian DLA
Debian DSA