Impact
The vulnerability is an incorrect authorization check in Chrome’s SiteIsolation feature that lets a remote attacker who has already compromised a renderer process bypass site isolation and load a privileged page. This flaw allows the attacker to gain elevated privileges inside the browser, potentially enabling access to sensitive data or further attacks against the host. The weakness is classified as CWE-863: Authorization Bypass Through User‑Controlled Key.
Affected Systems
Google Chrome browsers on all versions prior to 152.0.7977.65 are affected. The problem exists wherever the SiteIsolation mechanism is enabled and a renderer process can be compromised.
Risk and Exploitability
Based on the description the flaw has a medium severity in Chromium’s own scoring. The CVSS score is 3.1, and the EPSS score is <1% and KEV is not listed, indicating that exploitation is likely low. An attacker would need to first compromise a renderer process—typically by serving malicious HTML or exploiting another vulnerability—before leveraging this bypass. The flaw does not grant direct remote code execution, but it does elevate the attacker’s privileges within the browser, increasing the potential impact of any subsequent exploits.
OpenCVE Enrichment
Debian DLA
Debian DSA