Impact
Improper input validation in DevTools allows a remote attacker who has already compromised the renderer process to bypass Chrome's site isolation using a crafted HTML page. This can enable the attacker to read or modify data across isolated sites, potentially leading to cross‑origin leaks or unauthorized code execution. The weakness arises from CWE‑20, improper validation of user‑supplied input.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. The vulnerability exists in all builds that shipped before the patch in that release channel.
Risk and Exploitability
The exploit requires the attacker to control or influence the renderer process, a non‑trivial prerequisite. While the possibility of exploitation exists, the risk is moderated by the high effort needed to compromise the renderer. The CVSS score is 3.1, reflecting a low severity impact. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the impact of a successful bypass is significant due to the loss of isolation between sites.
OpenCVE Enrichment
Debian DLA
Debian DSA