Impact
An information leak in the Core component of Google Chrome versions prior to 152.0.7977.65 allows a remote attacker who has already compromised the renderer process to bypass site isolation through a specially crafted HTML page. This flaw permits the attacker to access data that should be confined to separate renderer instances, violating the browser’s isolation guarantees. The weakness is consistent with CWE-200, representing a vulnerability that can expose sensitive information.
Affected Systems
All installations of Google Chrome running any version earlier than 152.0.7977.65 are affected. The issue applies across platforms where Chrome operates, including Windows, macOS, and Linux, and affects both standard desktop builds and any deployment that relies on the same browser engine without updates.
Risk and Exploitability
Chromium rates this problem as medium severity; the CVSS score is 3.1, and the EPSS score is < 1%, indicating a low likelihood of widespread exploitation. To exploit the flaw, an attacker must first gain control over a renderer process, a non‑trivial prerequisite. While the bug exposes protected data, it does not provide direct remote code execution or denial of service, but it can facilitate data exfiltration or cross‑site content leakage if the attacker can craft the malicious page. The vulnerability is not listed in the CISA KEV catalog, suggesting minimal evidence of active exploitation at the time of reporting.
OpenCVE Enrichment
Debian DLA
Debian DSA