Impact
The vulnerability allows a remote attacker who has already compromised the Chrome renderer process to bypass the browser’s origin policy. By serving a specially crafted HTML page the attacker can read or modify data that normally belongs to another origin, exposing sensitive information or enabling further malicious activity. This flaw is due to improper input validation and is classified as CWE‑20.
Affected Systems
Google Chrome versions older than 152.0.7977.65 are affected. Users running a lower version are at risk if they visit untrusted sites that could host crafted pages.
Risk and Exploitability
The flaw has a CVSS score of 3.1, rated Medium on Chromium’s severity scale and is not currently listed in the CISA KEV catalog. Exploitation requires both a compromised renderer process and a social‑engineering step to get the user to open a malicious HTML page. The EPSS score is <1 %, indicating a very low probability of exploitation, but similar origin‑policy bypasses are considered high risk by vendor guidance. Until the update is installed users should avoid unknown sites and keep Chrome current.
OpenCVE Enrichment
Debian DLA
Debian DSA