Impact
The vulnerability is a missing authorization check in Chrome’s Network component that allows a remote attacker who has already compromised the renderer process to bypass site isolation. The attacker can craft a malicious HTML page that loads into the compromised renderer, effectively leaking information from other website contexts and potentially executing privileged code in the browser. The weakness identified is a missing access control (CWE‑862) that directly enables the bypass.
Affected Systems
Google Chrome users running versions earlier than 155.0.8059.39 are affected. The vulnerability applies to the stable channel of Chrome on all platforms supported by Google Chrome. Specific product details are limited to the Chrome browser itself, with no additional components identified.
Risk and Exploitability
The exploit requires the attacker to have already compromised the renderer process, which typically implies local compromise or the ability to inject malicious content into the browser. The risk is therefore not a purely remote, unauthenticated attack but a local privilege escalation within the browser environment. Since no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, the current exploitation likelihood is uncertain. However, the medium severity assigned by Chromium suggests that while exploitation is feasible, it may not be widely leveraged at present. Users should therefore treat this as a moderate to high in‑browser privilege escalation risk and apply the fix as soon as possible.
OpenCVE Enrichment