Impact
A bug in Chrome’s StorageAccessAPI performs an incorrect authorization check, letting a remote attacker who has already compromised the renderer process bypass the web origin policy. By serving a specially crafted HTML page, the attacker can read or manipulate storage for origins that should remain isolated, potentially exposing sensitive data. The Chrome security team rated the issue as low severity.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. The security fix is delivered through the stable channel update referenced in the Chrome release blog.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium risk, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so the risk assessment is based solely on the vendor’s low severity rating. Exploitation requires control of a renderer process that can serve a crafted page, limiting the attack surface to compromised renderer contexts only.
OpenCVE Enrichment
Debian DLA
Debian DSA