Impact
Insufficient policy enforcement in the Passwords component of Google Chrome versions prior to 149.0.7827.103 allows a remote attacker who has compromised the renderer process to bypass Chrome’s site isolation using a specially crafted HTML page. This flaw is an input validation failure, matching CWE‑20 and CWE‑1100, and it can enable the attacker to access or modify data belonging to other web origins, potentially leading to cross‑origin information disclosure or tampering.
Affected Systems
Google Chrome browsers running any version earlier than 149.0.7827.103 on desktop operating systems are affected. The vulnerability targets the renderer process and applies to all users who have not updated to the patched release.
Risk and Exploitability
The flaw is rated with a Chromium severity of High and a CVSS score of 8.1, reflecting significant severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to deliver a malicious HTML payload to a compromised renderer process, making the attack vector likely remote and content‑driven.
OpenCVE Enrichment
Debian DSA