Impact
The vulnerability is a missing authorization check in Chrome’s SiteIsolation mechanism. A remote attacker who has already compromised the renderer process can send a specially crafted PDF file to the browser, causing the renderer to bypass site isolation. This bypass lets the attacker read or modify data that should be confined to a separate site context, resulting in potential data leakage or credential theft. The issue is rated as medium severity by Chromium.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. All operating systems that ship Chrome and run these versions are vulnerable. Versions 152.0.7977.65 and later contain the fix.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. The CVSS score is 3.1, a medium severity, so exploitation is unlikely unless the attacker already has a compromised renderer process. Existing workstations on older Chrome versions remain at risk until patched. Although the vulnerability does not provide remote code execution, the ability to bypass site isolation poses a confidentiality risk that should not be ignored.
OpenCVE Enrichment
Debian DLA
Debian DSA