Impact
Improper input validation in the network component of Google Chrome allowed a remote attacker who had already compromised the renderer process to bypass the web origin policy via a crafted HTML page. The flaw permits violation of the same‑origin restriction, potentially enabling a malicious site to access resources from another origin or execute code in the context of trusted pages. The vulnerability is a classic input validation error (CWE‑20).
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are vulnerable. The CVE affects the network module that processes HTML content in the renderer process. The specific operating systems impacted are not explicitly detailed in the description; however, it is inferred that the vulnerability applies to all platforms where Chrome runs, as the network component is common across supported OS.
Risk and Exploitability
This CVE has a Chromium severity of medium, reflected by a CVSS score of 4.3. The EPSS score is less than 1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. The flaw requires the attacker to already control the renderer process, meaning local compromise or an earlier vulnerability. Attackers could then serve a malicious HTML page to bypass the origin policy. Because the attack vector depends on renderer control, the risk to remote unprivileged users is low unless a chain exists. The lack of a publicly disclosed exploit and the absence of a KEV listing suggest moderate risk, but patching remains recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA