Impact
Insufficient validation of untrusted input in the Loader component of Google Chrome before version 149.0.7827.53 allows a remote attacker who has already compromised the renderer process to bypass Chrome’s site isolation mechanism. The vulnerability can lead to cross‑site data exposure if an attacker can bypass isolation; this is inferred from the bypass capability. The Chromium security severity is reported as low, but the ability to break isolation between processes may pose a significant risk in a multi‑tenant or shared environment when combined with other flaws that allow renderer compromise.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. The vulnerability is specific to the Loader module used during page parsing and rendering inside Google Chrome’s renderer process.
Risk and Exploitability
The vulnerability requires that the attacker already has control over the renderer process, a condition that would normally arise from a previous compromise. No public exploit or published exploit code is known. The vulnerability is not listed in the CISA KEV catalog. The EPSS score is < 1%, indicating a very low probability of exploitation. The CVSS score is 3.1, which classifies the issue as low severity. Despite the low Chromium severity rating, breach of site isolation can create a risk in multi‑tenant or shared environments if other weaknesses allow renderer compromise.
OpenCVE Enrichment
Debian DSA