Impact
The vulnerability is a cross‑site scripting flaw in Chrome’s SanitizerAPI that allows an attacker to inject crafted HTML and bypass the browser’s web‑origin policy. This flaw falls under CWE‑79 and can enable a remote attacker to execute arbitrary script in the context of a trusted web origin, potentially exposing confidential data or hijacking the user’s session.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are impacted. Any system deploying these affected Chrome releases is susceptible until it is updated to a fixed version.
Risk and Exploitability
The flaw has a CVSS score of 4.3, denoting medium severity. Exploitation requires an attacker to host a malicious HTML page that a user visits; no local privilege escalation is needed. The EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating that public exploitation is currently unlikely but not impossible. Given the nature of the attack vector, the risk is moderate and should be addressed promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA