Impact
An incorrect reference resolution bug in Google Chrome’s Speech feature allows a remote attacker who has already compromised the renderer process to bypass the browser’s site isolation boundaries by loading a specially crafted HTML page. This enables the attacker to potentially access or manipulate cross‑site data that should be contained within separate processes, compromising confidentiality and integrity of isolated sites.
Affected Systems
The vulnerability affects Google Chrome versions prior to 152.0.7977.65 on all platforms that run the desktop stable channel. Any site that could be reached through the compromised renderer process is subject to a site isolation bypass.
Risk and Exploitability
The CVSS score of 3.1 indicates a Low severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first gain control of a renderer process, after which a crafted HTML page can trigger the reference resolution flaw. While no public exploits are reported, the potential for data leakage and cross‑site manipulation raises concerns for browsers that rely on site isolation for security.
OpenCVE Enrichment
Debian DLA
Debian DSA