Impact
Missing authorization in the Document Object Model of Google Chrome prior to version 153.0.8010.36 allows a remote attacker to craft an HTML page that can read page‑specific data that should be protected. The flaw arises from improper access control on DOM objects, which can expose confidential information if an attacker hosts a malicious page on a victim’s system. The impact is limited to reading data that is visible to the victim’s browser session and not altering it, so the threat is mainly information disclosure rather than code execution or service disruption.
Affected Systems
Google Chrome browsers running any version earlier than 153.0.8010.36 on desktop platforms are affected. The flaw originates from the Chrome rendering engine and does not depend on privileged system access, so all users of unsupported versions are at risk.
Risk and Exploitability
The vulnerability is classified with low severity by Chromium and is not listed in the CISA KEV catalog, and no EPSS score is available. This suggests that exploitation activity is currently low or unobserved. The attack vector is a remote crafted HTML page, which means a malicious website can potentially trigger it when a user visits the page. While the potential for information leakage exists, the lack of a known widespread exploit and low severity rating indicates a moderate risk for most users, but the vulnerability should still be remediated as soon as possible.
OpenCVE Enrichment