Impact
An inappropriate implementation in Chrome’s SiteIsolation feature allows a renderer process that an attacker has already compromised to bypass same‑origin policy restrictions when a crafted HTML page is loaded. The flaw effectively lets the malicious renderer read or execute code on other sites, elevating the attacker’s privileges to the level of the user’s browsing context. This weakness is classified as CWE‑653 and CWE‑693.
Affected Systems
Google Chrome binaries before 151.0.7922.72 are affected. The flaw exists in all Chrome releases up to that version, regardless of operating system, because the SiteIsolation logic is shared across platforms.
Risk and Exploitability
The CVSS score of 4.2 indicates medium severity. The EPSS score of less than 1% indicates that, at the time of this analysis, the probability of mass exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to first compromise the renderer process—typically via a separate vulnerability or social‑engineering attack—and then serve a specially crafted HTML page. The attack path is therefore indirect and depends on existing renderer compromises, but once established it can compromise data across multiple sites.
OpenCVE Enrichment
Debian DLA
Debian DSA