Impact
The vulnerability is an incorrect authorization check in the StorageAccessAPI used by Google Chrome. An attacker who has already compromised a renderer process can construct a crafted HTML page that causes the browser to bypass the same‑origin policy and access storage data belonging to a different origin. This flaw is a broken access control issue and can be used to read or modify data that should be protected by the web origin policy, potentially enabling credential theft or cross‑site data manipulation.
Affected Systems
Google Chrome browsers with versions earlier than 152.0.7977.65 are affected. Users running these build numbers are at risk if an attacker gains control of the renderer process.
Risk and Exploitability
The CVSS score is 6.5, and the EPSS score is less than 1%, indicating moderate severity with low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Exploitation requires a compromised renderer process, so the attack vector is not purely remote from the network but requires local compromise or sophisticated targeting. Overall, the risk is considered low to moderate with the current public information. However, any scenario that enables renderer compromise could lead to a full origin‑policy bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA