Impact
Missing authorization in the Document Object Model of Google Chrome prior to version 153.0.8010.36 allows a remote attacker to craft an HTML page that can read page‑specific data that should be protected. The flaw arises from improper access control on DOM objects, which can expose confidential information if an attacker hosts a malicious page on a victim’s system. The impact is limited to reading data that is visible to the victim’s browser session and does not alter it, so the threat is mainly information disclosure rather than code execution or service disruption.
Affected Systems
Google Chrome browsers running any version earlier than 153.0.8010.36 on desktop platforms are affected. The flaw originates from the Chrome rendering engine and does not depend on privileged system access, so all users of unsupported versions are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating medium severity. The EPSS score is below 1% and it is not listed in CISA KEV, suggesting the probability of exploitation is low and no widespread exploitation is known. The attack vector is a remote crafted HTML page, meaning a malicious website can potentially trigger it when a user visits the page. The defect allows an attacker to read page‑specific data that should be protected, leading to information disclosure rather than code execution or service disruption. While the overall risk is moderate, it should still be remediated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA