Impact
Missing authorization in the Lighthouse component of Google Chrome enabled a remote attacker who had already compromised the renderer process to bypass site isolation by serving a crafted HTML page. The vulnerability allows the attacker to access or manipulate data and resources across site boundaries, potentially compromising user confidentiality and integrity within the browser context.
Affected Systems
All desktop versions of Google Chrome released before 152.0.7977.65 were affected. The issue was addressed in the stable channel update for that release date.
Risk and Exploitability
Chromium rates this issue as low severity based on a CVSS score of 3.1. The EPSS score is < 1%, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires an initial compromise of the renderer process, often achieved through malicious content or social engineering. Once the renderer is compromised, the attacker can bypass site isolation and reach data from other sites. The risk is significant for environments relying on Chrome’s isolation features, but the likelihood of exploitation remains low due to the prerequisite of renderer compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA