Impact
A remote attacker who has already compromised the renderer process can provoke Chrome’s Back‑Forward Cache mechanism to exfiltrate data from a different origin. The flaw allows the attacker to construct a malicious HTML page that, when visited, coerces the browser into reading cached resources that belong to another site, exposing sensitive information. The weakness is a Privacy Violation – data that should remain confidential becomes accessible to a malicious renderer.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. Users running the stable channel prior to this build are at risk once a renderer process is compromised.
Risk and Exploitability
The CVSS score of 3.1 classifies this flaw as Low severity, indicating limited scope for exploitation. The EPSS score of <1% suggests a very low probability that the vulnerability will be actively targeted, and no public exploit has been documented. However, because the required conditions—a compromised renderer process and a crafted webpage—are conceivable, a determined attacker could trigger BFCache to read cross‑origin data, potentially exposing sensitive information. The vulnerability is not listed in the CISA KEV catalog. The attack path requires the attacker to deliver a malicious page that forces the browser to access cached resources from another origin.
OpenCVE Enrichment
Debian DLA
Debian DSA