Impact
The vulnerability arises from an inappropriate implementation within Chrome's plugin subsystem that permits a remote attacker who has already compromised a renderer process to bypass site isolation when delivering a crafted HTML page. Based on the description, it is inferred that this bypass may expose confidential data from isolated browsing contexts and could allow further exploitation, as deemed high severity by Chromium security. The issue corresponds to CWE‑346 and CWE‑653.
Affected Systems
Affected vendor is Google, product Chrome, and all desktop installations running any version earlier than 149.0.7827.103 remain vulnerable. No additional version specifics were provided beyond the update that introduced the fix. Users running the patched version are not exposed to this flaw.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in CISA's KEV catalog, however the CVE carries a CVSS score of 8.1. The attacker must first compromise a renderer process, and once this foothold is achieved, a crafted HTML page can override site isolation controls to read data across origins. Based on the description, it is inferred that the initial renderer compromise likely requires high privileges or sophisticated exploitation. The flaw corresponds to CWE‑346. While no publicly available exploit was cited as of this analysis, the potential for data leakage makes the threat significant for systems with outdated Chrome installations.
OpenCVE Enrichment
Debian DSA