Impact
Insufficient policy enforcement in the Passwords module of Google Chrome before version 149.0.7827.103 allows a remote attacker who has already compromised the renderer process to bypass Chrome’s site isolation mechanism using a specially crafted HTML page. This flaw is a direct denial of the intended process isolation, which can enable the attacker to access or manipulate data belonging to other web origins, potentially leading to cross‑origin information disclosure or tampering. The weakness is a classic input validation failure, corresponding to CWE‑20.
Affected Systems
Google Chrome browsers running any version prior to 149.0.7827.103 are affected. The vulnerability specifically targets the renderer process in desktop builds of Chrome, impacting users who have not updated to the patched release.
Risk and Exploitability
The vulnerability carries a Chromium severity classification of High and is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Because the exploit requires a malicious payload in the renderer process, the likely attack vector is a remote attacker delivering crafted HTML content to a compromised renderer. The EPSS value is not available, but based on the high severity and lack of public exploitation data, the risk is considered significant for environments that run unpatched Chrome versions.
OpenCVE Enrichment