Impact
The flaw is an instance of CWE‑20 Improper Input Validation in the Input module of Google Chrome. Before the 152.0.7977.65 release, a compromised renderer process could be supplied with a maliciously crafted HTML page that lets the attacker read or execute content from origins that should be isolated. The result is a loss of origin boundary integrity, allowing cross‑origin data leakage. The threat does not grant arbitrary code execution by itself; it depends on prior renderer compromise and social engineering to provide the malicious page.
Affected Systems
All Google Chrome installations on Windows, macOS, and Linux using the stable renderer engine before version 152.0.7977.65 are affected. Any environment that runs Chrome with older versions is vulnerable regardless of operating system.
Risk and Exploitability
Chromium rates this as Medium security severity. The CVSS score is 4.3, reflecting the requirement that the attacker must first break out of the renderer sandbox. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating low current exploit probability. The attack vector is user interaction with malicious content, usually via social engineering. Once conditions are met, the origin policy can be bypassed, exposing cross‑origin data but not allowing remote code execution without further compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA