Impact
Google Chrome’s navigation code performs improper input validation, which allows a crafted HTML page to convince the renderer process that the page should bypass site isolation. When a remote attacker has already compromised the renderer, this flaw lets the attacker exceed the isolation boundaries normally enforced between sites, potentially leading to cross‑site data leakage or privilege escalation. The weakness is a classic input validation issue identified as CWE‑20.
Affected Systems
All Google Chrome installations older than version 152.0.7977.65 are affected. The CVE applies to the stable channel releases that have not yet incorporated the 152.0.7977.65 update.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the vulnerability is listed with a Medium severity in Chromium’s own scoring. EPSS score is less than 1%, indicating a very low probability of exploitation. The issue is not in the CISA KEV catalog, which suggests that widespread exploitation has not yet been observed. A remote attacker must first compromise a renderer process, a non‑trivial prerequisite, so the likelihood of exploitation is moderate under realistic attack conditions. Once the precondition is met, the attacker can bypass site isolation, which would grant access to data and resources from other sites rendered in separate processes.
OpenCVE Enrichment
Debian DLA
Debian DSA