Impact
An incomplete cleanup in SiteIsolation in Google Chrome versions prior to 152.0.7977.65 enables a remote attacker who has already compromised the renderer process to bypass site isolation by loading a crafted HTML page. The vulnerability does not directly allow arbitrary code execution or privilege escalation, but it removes an important security boundary that isolates sites, potentially allowing a malicious site to interact with resources from another site. The primary weakness is a flaw in the site's isolation cleanup logic (CWE‑459).
Affected Systems
Google Chrome installations on desktop platforms running any version before 152.0.7977.65 are affected. No specific build or platform limitations are indicated beyond the version threshold.
Risk and Exploitability
The CVSS score of 3.1 indicates medium severity in the National Vulnerability Database. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation evidence. An attacker would still need to obtain a foothold in the renderer process, a non‑trivial prerequisite. Therefore, while the potential impact is significant if the precondition is met, the overall likelihood of exploitation in the wild remains low to moderate pending better exploitation evidence.
OpenCVE Enrichment
Debian DLA
Debian DSA