Impact
The vulnerability is an incorrect authorization check in Google Chrome’s SiteIsolation feature. It allows a remote attacker who has already compromised the renderer process to bypass site isolation by serving a crafted HTML page. This flaw enables the attacker to act with privileges beyond those granted to a normal renderer process, according to the CWE‑863 classification.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 on any platform are affected, including the stable channel. Any user running an older version of Chrome that may be exposed to a compromised renderer process is vulnerable.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score is less than 1%, suggesting a low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires an initial compromise of the renderer process and the use of social engineering to deliver a crafted HTML page. While the attack surface is limited by the need for that preexisting compromise, the impact on confidentiality and integrity within the browser is notable if the renderer is subverted.
OpenCVE Enrichment
Debian DLA
Debian DSA