Impact
The flaw lies in Chrome’s StorageAccessAPI, where input from a crafted HTML page is not properly validated. An attacker who can compromise the renderer process – a condition confirmed by the description – can exploit this to bypass the browser’s same‑origin policy. This bypass allows unauthorized read or write of data that should be origin‑restricted, resulting in the loss or alteration of user data. The vulnerability is classified as medium severity by Chromium.
Affected Systems
All installations of Google Chrome with a version earlier than 152.0.7977.65 are affected, regardless of channel. Versions 152.0.7977.65 and newer include the fix.
Risk and Exploitability
The vulnerability requires a renderer process compromise. The description does not specify an external exploit path. With an EPSS score of less than 1% and no listing in CISA’s KEV catalog, the likelihood of widespread exploitation is uncertain, and the CVSS score of 4.3 indicates a medium level of risk. If a renderer compromise occurs, the crafted HTML can trigger the invalid input handling, achieving a policy bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA