Impact
A crafted HTML page can trigger an improper resource exposure in the Preload feature of Google Chrome prior to version 152.0.7977.65, allowing a remote attacker to bypass Chrome’s site isolation. The result is that an attacker could access or inject content into a different site’s isolated context, potentially exposing sensitive data or injecting malicious code. The weakness is identified as CWE‑668: Improper Resource Exposure.
Affected Systems
All users running Google Chrome versions earlier than 152.0.7977.65 are affected. The vulnerability is limited to desktop Chrome installations that support the Preload feature.
Risk and Exploitability
The CVE has a CVSS score of 3.1 (Medium). The EPSS score is below 1%, indicating a low exploitation probability, and it is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, relying on a malicious HTML page that a user must visit. Bypassing site isolation could allow attackers to read or manipulate content across site boundaries, posing a significant confidentiality and integrity risk.
OpenCVE Enrichment
Debian DLA
Debian DSA