Impact
An improper state validation issue in Chrome's SafeBrowsing feature permits a remote attacker to craft an HTML page that, when opened in the browser, bypasses Chrome's system access restrictions. The flaw is linked to CWE‑754 and CWE‑79 and is classified by Chromium as a medium‑severity vulnerability.
Affected Systems
Google Chrome versions older than 153.0.8010.36 are affected. The vulnerability is presumed to target desktop installations of Chrome; this inference is drawn from the product description and the published desktop stable‑channel update that introduced the fix.
Risk and Exploitability
The flaw requires the victim to load a specifically crafted HTML page; no additional network or privilege prerequisites are listed. The EPSS score is under 1 %, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.4 signals medium severity. The likely attack vector is a user visiting or opening malicious HTML content in Chrome, after which the attacker may gain unauthorized system access depending on the browser’s access restrictions.
OpenCVE Enrichment
Debian DLA
Debian DSA