Impact
Improper input validation in the handling of Cookies in Google Chrome versions prior to 152.0.7977.65 enables a remote attacker who has already compromised the renderer process to bypass the web origin policy through a specially crafted HTML page. The attacker can then access web pages and resources from other origins, potentially exfiltrating data or executing unauthorized actions. The vulnerability is a classic example of CWE-20, input validation errors that allow unintended control over data flow within a web application.
Affected Systems
All platforms that run Google Chrome with a version older than 152.0.7977.65 are affected, regardless of the operating system or deployment environment. Versions 152.0.7977.65 and newer contain a fix that validates cookie input correctly and restores the origin policy enforcement.
Risk and Exploitability
The CVE has a CVSS score of 6.5, indicating medium severity, and is not listed in the CISA KEV catalog. The EPSS score is less than 1%, suggesting a very low exploitation probability. Because exploitation requires that the renderer process already be compromised, the attack vector is indirect and may involve malware or phishing that first gains renderer access. While the weakness allows cross‑origin attacks, the overall risk is moderate, and the flaw is not presently known to be actively exploited in the wild.
OpenCVE Enrichment
Debian DLA
Debian DSA