Impact
The vulnerability is an insufficient validation of untrusted input in the Passwords component of Google Chrome. When a remote attacker has already compromised the renderer process, a specially crafted HTML page can be used to bypass site isolation.
Affected Systems
Google Chrome versions earlier than 151.0.7922.72 are affected. All systems running these versions are susceptible until the update is applied.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity level, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to compromise the renderer process first, which can occur through unrelated vulnerabilities or social engineering, and then deliver a crafted page to bypass site isolation.
OpenCVE Enrichment
Debian DLA
Debian DSA