Impact
The CVE highlights an insecure handling of input within Chrome extensions that allows an attacker who has already compromised the renderer process to bypass site isolation via a crafted HTML page. This flaw, classified as CWE‑20, was rated high severity by Chromium security, indicating that the implementation can be abused to undermine the boundary that normally prevents web content from one origin from accessing content from another.
Affected Systems
Google Chrome desktop browser versions released prior to 149.0.7827.103 are affected. The flaw is present in the browser’s extensions subsystem and does not affect non‑extension components.
Risk and Exploitability
Exploitation requires the attacker to first gain control over the renderer process, which could be achieved through a malicious extension or a compromised website. Once that condition is met, the attacker can serve a specially crafted HTML page to the renderer to lift it out of its isolated context. The CVSS score of 6.5 denotes moderate‑to‑high severity, while the EPSS score of <1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA