Impact
A race condition in the Workers component of Google Chrome allows an attacker who has already compromised the renderer process to circumvent the web origin policy through a specifically crafted HTML page. The flaw enables the bypass of the same‑origin restriction, potentially allowing the attacker to read or manipulate data from origins that should be isolated. The vulnerability is classified as medium severity in Chromium’s internal ranking.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. Users running these releases are susceptible to the race condition described above.
Risk and Exploitability
The vulnerability’s CVSS score is 4.3, with an EPSS score of < 1% and it is not listed in the CISA KEV catalog. Because exploitation requires the renderer process to already be compromised, the attack vector is inferred to be a remote attacker who can inject malicious content into that process. Once the renderer is hijacked, a cross‑origin policy bypass can be performed, making the forgery capable of exfiltrating sensitive information from other origins. The overall risk is moderate, as the requirement for a prior compromise reduces the likelihood of an initial breach but considerably increases the impact once achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA