Impact
Based on the description, it is inferred that improper input validation in the ReadingList feature of Google Chrome on Windows allowed a remote attacker who had already compromised the renderer process to bypass the browser’s same‑origin policy. This flaw permits a malicious origin to access data or resources that should be sandboxed, effectively allowing unauthorized access to the victim's browsing context. The weakness originates from insufficient validation of input parameters, mapping to CWE‑20.
Affected Systems
Google Chrome version 152.0.7977.64 and earlier running on Windows operating systems are affected. The vulnerability is specific to the Windows builds of Chrome and targets the ReadingList component, which is enabled by default in stable channel releases.
Risk and Exploitability
Based on the description, it is inferred that an attacker must first gain control of the renderer process, which typically requires exploiting another vulnerability or using a malicious website. Once renderer control is obtained, the crafted HTML page can exploit this flaw to bypass the browser’s same‑origin policy. The likely attack vector involves a malicious website delivering a crafted HTML page to the victim, which during an existing renderer process compromise enables the policy bypass. The CVSS score of 6.5 indicates a medium overall severity, and although the vulnerability is not listed in CISA’s KEV catalog, the existence of the bypass makes it a relevant concern for environments where origin isolation is critical. The EPSS score is < 1%, indicating a low likelihood of exploitation, but the potential impact of data exposure warrants attention.
OpenCVE Enrichment
Debian DLA
Debian DSA