Impact
This vulnerability arises from incorrect authorization checks in the SiteIsolation component of Google Chrome. When an attacker can influence the renderer process, a crafted HTML page can trick the browser into treating content from another origin as if it belonged to the same site. The resulting breach bypasses the intended isolation, exposing data or credentials that should be protected by site boundaries.
Affected Systems
Google Chrome on Windows, macOS, Linux, and Android running any build prior to version 152.0.7977.65. All users of these operating system families must update to the patched release to prevent exploitation.
Risk and Exploitability
The Chromium project rates this issue as Medium. The CVSS score is 3.1, reflecting a low‑to‑medium severity. The EPSS score is 0.00377, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate current exploitation risk. An attacker would need to have already compromised the renderer process—typically via a malicious web page or script—before delivering the crafted content. Once the renderer is compromised, the SiteIsolation bypass grants the attacker full read/write access to all data belonging to the targeted site.
OpenCVE Enrichment
Debian DLA
Debian DSA