Impact
The vulnerability allows a malicious or deceptive installation of a Chrome extension to read data from other origins, effectively leaking confidential information. The flaw is an Information Exposure weakness (CWE‑200), which permits extraction of data that the user did not intend to share, potentially compromising the confidentiality of browsing information such as personal data, credentials or other sensitive data present in cross‑origin sites.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are affected. The issue is specific to the desktop stable channel of Chrome on all platforms that run the affected build.
Risk and Exploitability
The CVE has a CVSS score of 4.3, which corresponds to Medium severity according to Chromium’s assessment. The EPSS score is below 1 %, indicating a very low but non‑zero probability of exploitation, and it is not listed in the CISA KEV catalog. The flaw is exploited through social engineering that tricks a user into installing a malicious Chrome extension; once installed, the extension can read cross‑origin data from any site the user visits, resulting in unbounded data leakage. Because the attack requires user interaction, the likelihood of exploitation is moderate but remains significant, particularly in environments where users can install extensions freely.
OpenCVE Enrichment
Debian DLA
Debian DSA