Impact
This vulnerability allows a remote attacker to access data from a different origin by loading a specially crafted HTML page in Google Chrome prior to version 153.0.8010.52. The flaw resides in the handling of permissions, enabling the extraction of cross‑origin information. The impact is information disclosure (CWE‑200), which can compromise user privacy or confidential data without requiring elevated privileges.
Affected Systems
Google Chrome versions prior to 153.0.8010.52, including desktop builds, are affected. The CVE description does not list specific minor versions, so the exact scope of earlier releases is unspecified. The flaw exists in the Permissions module that manages cross‑origin access to resources. Mobile versions are not mentioned in the advisory. It is likely that earlier releases such as 152.x and earlier are vulnerable, but the CVE does not explicitly confirm this.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level, and the EPSS score of < 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but it can still be exploited by an attacker who can serve a malicious HTML page to a victim’s browser. The likely attack path is a remote web page that triggers the permissions check, leading to cross‑origin data leakage. Since the attack requires only the victim to load a crafted page, the vector is remote user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA