Impact
A flaw in the Navigation component of Google Chrome allowed an attacker who had already compromised the renderer process to bypass site isolation protections by serving a specially crafted HTML page. The insufficient validation of untrusted input enables the attacker to access or manipulate data that should be isolated between different web sites, potentially leading to data leakage or unauthorized data access within the browser context.
Affected Systems
Google Chrome browsers running any version prior to 149.0.7827.53 are affected. No specific sub‑versions are listed beyond this cutoff, so all releases earlier than the mentioned build should be considered vulnerable.
Risk and Exploitability
Chromium rates the vulnerability as low severity and the CVSS score is 6.5, while the EPSS score indicates a risk below 1%. The vulnerability is listed as not part of CISA's KEV catalog. Exploitation requires the attacker to have already compromised the renderer process and depend on a crafted HTML page delivered to that process. As such, the risk is confined to environments where renderer isolation can be subverted, and the attack vector is remote via a malicious web page.
OpenCVE Enrichment
Debian DSA