Impact
Improper input validation in Chrome's Preload feature allows a remote attacker who has compromised the renderer process to bypass the browser's web origin policy by serving a specially crafted HTML page. The flaw is a CWE‑20 input validation weakness. This bypass could let the attacker access resources that should be isolated by origin, such as reading data from other sites loaded in the same tab or injecting malicious content. The CVE description does not explicitly confirm further exploitation, so any impact beyond policy bypass is inferred from the stated behavior.
Affected Systems
This vulnerability affects all Google Chrome versions released before 152.0.7977.65 that include the Preload feature, across all operating systems and platforms supported by that release. End users of the stable channel should verify their installed Chrome build and plan an update if they are running a vulnerable version.
Risk and Exploitability
The CVSS score is 4.3, and the EPSS score is < 1%, indicating that the exploitation probability is not well characterized. The vulnerability is not listed in the CISA KEV catalog, suggesting there are no known active exploits in the wild. The attacker needs prior compromise of the renderer process to exploit the flaw, which is a non‑trivial prerequisite. Overall, the risk is moderate, and the most effective mitigation is to apply the vendor‑provided fix.
OpenCVE Enrichment
Debian DLA
Debian DSA