Impact
Improper input validation in the WebRTC component of Google Chrome releases up to 152.0.7977.64 allows a remote attacker with access to a compromised renderer process to supply a specially crafted HTML page. The flaw lets the attacker circumvent the browser’s web origin security model, potentially exposing data or executing scripts across origin boundaries. This vulnerability is defined as a constraint on Input Validation (CWE‑20) and is rated medium severity by Chromium’s internal scoring.
Affected Systems
Google Chrome versions before 152.0.7977.65 are affected.
Risk and Exploitability
The CVSS score is 3.1, but the vulnerability is listed as medium severity by Chromium. The EPSS metric is <1%, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread known exploitation. However, the attack requires an attacker to have already compromised the renderer process, which typically necessitates a separate exploitation vector. Once that condition is met, the attacker can deliver a malicious HTML page that evades the origin policy. While exploitation complexity is high, the damage potential is significant if cross‑origin data leakage or script execution occurs.
OpenCVE Enrichment
Debian DLA
Debian DSA