Impact
The CVE describes incorrect authorization in Chrome's DeviceBoundSessionCredentials that lets a remote attacker craft network traffic to bypass the browser’s web origin policy. By escaping this policy, the attacker could read or modify data intended for a different origin, enabling cross‑origin information theft or tampering. This weakness reflects improper authentication (CWE‑346) and improper authorization (CWE‑863).
Affected Systems
The vulnerability affects Google Chrome versions older than 153.0.8010.36. Users running any earlier build are susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. No EPSS data or KEV entry is available. The exploit likelihood is uncertain, yet the remote nature of the attack suggests that a sophisticated attacker could serve crafted traffic to trigger the bypass. Until a patch is deployed, the risk remains moderate but worth addressing promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA