Impact
Google Chrome allowed an untrusted HTML payload delivered to an extension to be insufficiently validated, giving a remote attacker who had already breached the renderer process the ability to bypass site isolation. The flaw enables the attacker to access data and functionalities of other web pages that should be isolated, potentially leading to data theft or the execution of unauthorized scripts across origins. The weakness is an example of CWE‑20, insufficient input validation.
Affected Systems
Google Chrome, all releases prior to 149.0.7827.103. The vulnerability applies to desktop versions of Chrome where extensions can load untrusted content.
Risk and Exploitability
Chrome’s highest severity rating for the vulnerability is High. Because the attacker must first compromise the renderer process, the risk is dependent on the likelihood of such a foothold. EPSS information is not available, and the flaw is not currently listed in the CISA KEV catalog. The key exploitable condition is the ability for a crafted HTML page to over‑ride site isolation controls once a renderer process has been subverted.
OpenCVE Enrichment