Impact
Improper input validation in Chrome’s network stack enables an attacker to craft an HTML page that can bypass the browser's origin policy. By violating this isolation boundary, the attacker may access resources, data, or session information from other origins, potentially leading to data theft or session hijacking. Chromium has rated the flaw as medium severity.
Affected Systems
The flaw affects Google Chrome browsers prior to version 152.0.7977.65. All builds before this revision are vulnerable until a patch is applied.
Risk and Exploitability
The EPSS score is less than 1% and the CVSS score of 4.3 indicates medium severity. The vulnerability is not listed in CISA KEV, indicating no confirmed active exploitation at this time. The likely attack vector is a remote attacker delivering a crafted web page that the user opens, which triggers the origin policy bypass. Although the flaw does not grant arbitrary code execution, it offers a moderate risk by compromising cross‑origin isolation until mitigated by updating the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA