Impact
An insufficient policy enforcement flaw in the Media component of Google Chrome on Windows allows a remote attacker to bypass the browser’s site isolation boundary by serving a specially crafted HTML page. This improper access control issue (CWE‑602) lets the attacker read or modify data that is normally confined to a separate process, undermining cross‑site confidentiality and integrity.
Affected Systems
All Windows installations of Google Chrome running a version earlier than 150.0.7871.47 are affected. Based on the description, it appears that no equivalent problem is documented for macOS or Linux distributions.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity, while the EPSS score of <1% shows a very low probability of widespread exploitation. Although the vulnerability is not listed in CISA’s KEV, the breach of site isolation could grant an attacker unauthorized access to multiple sites and browser processes. Based on the description, the likely attack vector is remote: the attacker delivers a malicious HTML page that triggers user visits a crafted web page.
OpenCVE Enrichment
Debian DLA
Debian DSA