Impact
Google Chrome versions before 151.0.7922.72 contain a policy bypass that lets a malicious extension circumvent the browser’s site isolation, effectively giving the extension the same privileges it would have if it were running in the same process as arbitrary web content. This flaw is a classic example of an authorization and access‑control weakness, classified under CWE‑653 and CWE‑693. The result is that an attacker who lures a user into installing such an extension can read, modify or inject data into pages from other sites or tabs, potentially leading to credential theft, phishing, or further exploitation of the user’s system.
Affected Systems
Google Chrome versions earlier than 151.0.7922.72 are susceptible to this policy bypass. Users who install third‑party extensions from sources other than the official Chrome Web Store may expose themselves to this vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity issue, while the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires social engineering to convince a user to install a crafted extension; once installed, the extension can bypass site isolation and read or modify data from other tabs or sites.
OpenCVE Enrichment
Debian DLA
Debian DSA