Impact
The vulnerability arises from insufficient policy enforcement in Google Chrome’s GuestView component. A renderer process that has already been compromised can inject a specially crafted HTML page that bypasses Chrome’s site isolation rules. This issue allows an attacker to escape the isolation boundaries between tabs, extensions, or other isolated contexts, enabling access to protected data or processes. The weakness maps to CWE‑602, which describes inadequate control of access to protected resources.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 are affected. Users running these older versions with an attacker can compromise a renderer process.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1% denotes a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, so no known widespread exploitation exists. Based on the description, it is inferred that an attacker must first compromise a renderer process—likely through a separate flaw—before delivering the malicious content that triggers the GuestView policy bypass. This two‑stage requirement reduces the overall likelihood compared to single‑stage exploits.
OpenCVE Enrichment
Debian DLA
Debian DSA