Impact
The vulnerability is a missing authorization check in the FedCM module of Google Chrome which allows a remote attacker to serve a crafted HTML page that bypasses the browser’s web origin policy. This flaw can enable an attacker to read or manipulate data that is normally protected by the same‑origin policy.
Affected Systems
Google Chrome browsers prior to version 153.0.8010.36 on all supported platforms are affected.
Risk and Exploitability
Chromium lists the issue with a CVSS score of 4.3 (Medium). The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attack via a crafted HTML page loaded into Chrome; no elevated privileges or local access are required.
OpenCVE Enrichment
Debian DLA
Debian DSA