Impact
The vulnerability stems from incorrect reference resolution in the Cache component of Google Chrome before version 152.0.7977.65. A remote attacker can serve a crafted HTML page that causes the browser to misinterpret references, enabling the attacker to bypass the browser’s web origin policy. This flaw allows the attacker to access resources or perform actions that should be restricted by origin boundaries, potentially compromising user data or allowing further malicious activity.
Affected Systems
All users running Google Chrome with a version earlier than 152.0.7977.65 are affected. The issue is specific to the Chrome desktop stable channel; newer releases receive the fix within the same update cycle.
Risk and Exploitability
The flaw can be exploited remotely through a malicious web page. The EPSS score indicates a very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. While the Chromium project rates the severity as Medium, corresponding to a CVSS score of 4.3, the ability to break origin isolation poses a significant threat to confidentiality and integrity of user data if the attacker can deliver the crafted page. The attack vector relies on network delivery of manipulated content, so hosting or injecting content into a trusted site would likely be required.
OpenCVE Enrichment
Debian DLA
Debian DSA