Impact
Improper input validation in the NTP Footer feature of Google Chrome for Windows allows a remote attacker who has already compromised the renderer process to bypass the browser’s web origin policy by supplying a specially crafted HTML page. This bypass could enable the attacker to read or modify content from other origins, potentially leading to data theft or injection of malicious code. The weakness is identified as CWE‑20.
Affected Systems
The flaw affects Google Chrome running on Windows machines with versions earlier than 152.0.7977.65. Any installation that has not been updated to at least the 152.0.7977.65 stable release is vulnerable, regardless of the operating system build or user account privileges.
Risk and Exploitability
The vulnerability received a low severity rating by Chromium, and the CVSS score is now 6.5. EPSS is < 1% and the issue is not listed in the CISA KEV catalog. Exploitation requires that an attacker already gains code execution in the renderer process, which is a separate and non‑publicly available attack vector. Because the privilege escalation is limited to the renderer and the exploit is not readily available, the overall risk to users is considered low, but updates should be applied promptly to remove the capability.
OpenCVE Enrichment
Debian DLA
Debian DSA