Impact
Insufficient validation of untrusted input in Chrome's navigation component allowed an attacker who had already compromised the renderer process to bypass site isolation by serving a specially crafted HTML page. This flaw can let the attacker access or control web content that should be isolated, potentially resulting in cross‑origin data leaks or control.
Affected Systems
Google Chrome versions earlier than 149.0.7827.197 are vulnerable. The affected product is Google Chrome; versions prior to 149.0.7827.197 should be upgraded.
Risk and Exploitability
The vulnerability is classified as high severity but its EPSS score is not available. It is not listed in CISA KEV. Exploitation requires an attacker to gain control of the renderer process, which is a non‑trivial prerequisite. If achieved, the flaw can be leveraged to bypass browser security boundaries.
OpenCVE Enrichment