Impact
The vulnerability is a missing authorization check in the Viz component of Google Chrome, allowing a remote attacker who has compromised the renderer process to create a crafted HTML page that bypasses the web origin policy. This flaw falls under CWE-862 and could be leveraged to access resources across origins that should remain isolated, potentially exposing confidential data or allowing malicious script execution within trusted web contexts. The Chrome security severity rating for this issue is Medium, indicating a moderate risk if exploited.
Affected Systems
Google Chrome users running any build prior to version 152.0.7977.65 are affected. The issue is limited to the renderer process and does not directly impact other Chrome components or operating systems, but the renderer host must already be compromised for exploitation to occur.
Risk and Exploitability
The exploit requires an attacker to already have compromised the renderer process, which typically would involve delivering malicious content to the user or exploiting another Chrome component. Because it is not listed in the CISA KEV catalog, the EPSS score is less than 1% and the CVSS score is 4.3, the current information suggests a moderate exploit likelihood; it is not the most common attack vector for Chrome browsers. Once the renderer is compromised, the crafted HTML can cross origin boundaries, enabling access to sensitive information exposed through other web processes. The absence of a public exploit report and the limited scope of the flaw reduce the immediate risk, but the potential for cross‑origin data leakage warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA