Impact
A vulnerability in Google Chrome’s Safe Browsing feature allows a remote attacker to craft an HTML page that bypasses system access restrictions. The weakness is an improper state validation that can be triggered by a maliciously constructed page. As a result, an attacker could gain unauthorized access to system resources normally protected by browser isolation policies.
Affected Systems
The flaw impacts all Chrome releases prior to version 153.0.8010.36, affecting users of the Google Chrome browser across all supported platforms.
Risk and Exploitability
Chromium rates the severity of the issue with a CVSS score of 5.4, indicating moderate severity. The EPSS score is less than 1%, indicating a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack requires only a crafted HTML page delivered to a victim’s browser, implying a remote exploitation over the web with modest effort. With a CVSS score of 5.4, the risk is moderate, suggesting that exploitation would be limited to the browser context and may be mitigated by user awareness and timely patching.
OpenCVE Enrichment
Debian DLA
Debian DSA