Impact
An improper input validation flaw in the Network component of Google Chrome allows a renderer process that is already compromised to bypass system access restrictions by loading a specially crafted HTML page. The bug permits malicious content to escape the sandboxed renderer and access normally blocked resources, effectively elevating privileges within the browser context. This weakness is identified as CWE-20.
Affected Systems
The vulnerability affects Google Chrome versions prior to 152.0.7977.65 across all supported operating systems. Users running any of those releases are susceptible unless updated.
Risk and Exploitability
The flaw requires the attacker to first compromise the renderer process, typically via malicious web content or a separate exploit. The EPSS score is <1%, indicating a low likelihood of exploitation today, while the CVSS score of 6.8 reflects a medium severity level. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. Nonetheless, organizations should treat it as a potentially significant risk if the renderer is compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA