Impact
Incorrect authorization in the Input component of Google Chrome prior to version 152.0.7977.65 permits a remote attacker who has already compromised the renderer process to bypass the browser’s same‑origin policy through a specially crafted HTML page. This flaw could enable the attacker to read or manipulate data across origin boundaries, leading to potential theft of confidential information or credential leakage. The severity of the issue is rated medium.
Affected Systems
All installations of Google Chrome running any version earlier than 152.0.7977.65 are affected. The vulnerability exists across all platforms where the renderer process is used.
Risk and Exploitability
The exploit requires the attacker to first gain control of the renderer process, which may arise from other local or remote vulnerabilities. Once this condition is met, the attacker can deliver a crafted webpage that triggers the Input authorization error and violates the origin policy. No publicly available exploit code or proof‑of‑concept is known, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 4.3, and the EPSS score is <1%, indicating a low but non‑zero likelihood of exploitation. Overall, the risk remains moderate, contingent on the presence of a renderer compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA