Impact
The flaw is an incorrect authorization check in Chrome’s Network component that, prior to version 152.0.7977.65, allows a remote attacker who has already compromised the renderer process to bypass site isolation by serving a specially crafted HTML page. The flaw does not enable arbitrary code execution by itself; it simply removes the boundary that normally prevents a malicious page from accessing or interfering with data from other sites. The weakness is classified as an authorization bypass (CWE-863).
Affected Systems
All installations of Google Chrome older than 152.0.7977.65 are affected. The vulnerability impacts every supported operating system because Chrome’s network layer and renderer are common across platforms. Users who remain on earlier releases of the browser remain exposed until they upgrade.
Risk and Exploitability
Chromium rates the issue as Medium, with a CVSS score of 3.1. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Exploitation requires an attacker first to gain control of the renderer process, typically by luring the user to load malicious web content. Once renderer compromise is achieved, the crafted HTML triggers the authorization bypass and breaks the isolation boundary, exposing the affected user to potential data theft or phishing. The overall risk is moderate to high for users who navigate untrusted content, but the absence of widespread exploitation reduces immediate urgency.
OpenCVE Enrichment
Debian DLA
Debian DSA