Impact
An incorrect authorization check in Chrome’s Core module allows an attacker who has already compromised the renderer process to bypass the browser’s web origin policy. The flaw is triggered by a crafted HTML page and can enable the attacker to read, alter, or send requests to resources that would normally be protected by the same‑origin restriction. The impact is limited to the context of the compromised renderer and does not directly allow remote code execution on the host.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. The vulnerability was reported as affecting the stable channel and is referenced by the Chrome Stable Channel Update for Desktop and Chromium issue 497269030.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low exploitation probability. The CVSS score of 4.3 classifies the vulnerability as Medium severity. The vulnerability is not listed in the CISA KEV catalog, aligning with its low exploitation likelihood. However, exploitability requires the attacker to first compromise the renderer process, likely through another flaw or social engineering. Once that prerequisite is met, the attacker can use a specially crafted HTML page to violate the same‑origin policy, potentially compromising confidential data accessed by the affected context or facilitating further attacks within the browser environment.
OpenCVE Enrichment
Debian DLA
Debian DSA