Impact
Chrome versions before 153.0.8010.36 contain a flaw that allows a remote attacker to bypass normal source‑level authorization checks. A malicious web page can be crafted so that the browser will expose sensitive information it normally would not reveal through the web UI. The primary impact is non‑repudiation and confidentiality – data that the user expects to be kept private can leak to an attacker. This weakness stems from a misuse of authorization controls, identified as CWE‑863.
Affected Systems
The vulnerability affects Google Chrome across all platforms – Windows, macOS, Linux, iOS and Android – for releases earlier than 153.0.8010.36. Any installation that has not been updated to at least this version remains susceptible.
Risk and Exploitability
The Chromium security team classifies this issue as Low severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Nonetheless, the flaw can be triggered by an attacker through social engineering: an unsuspecting user must open a maliciously crafted HTML page or file. While the likelihood of exploitation is low, once the conditions are met the attacker can obtain confidential data from the victim's browser. Additionally, the CVSS score of 6.5 reflects a moderate risk.
OpenCVE Enrichment
Debian DLA
Debian DSA