Impact
The flaw is an inappropriate implementation of the ORB component in Google Chrome versions prior to 148.0.7778.96, a CWE‑269 weakness that allows a remote attacker to bypass the browser’s site isolation boundaries through a specially crafted HTML page. This bypass can enable the attacker to read or manipulate data from sites that should remain isolated, potentially leading to cross‑site data leakage, cookie theft, or privilege escalation within the browser.
Affected Systems
The vulnerability affects Google Chrome desktop browsers on all platforms running any build before 148.0.7778.96. Users of the stable release channel prior to that build are therefore vulnerable; newer releases contain the fix.
Risk and Exploitability
The attack requires a remote malicious web page hosted by the attacker; no special software or network infrastructure is needed on the victim side. The CVSS score of 6.3 indicates medium severity, and the EPSS score is unavailable, while the vulnerability is not listed in CISA KEV. Consequently the likelihood of exploitation is unclear, but the ability to bypass a core security boundary implies a notable risk for users who visit untrusted or mixed‑content sites.
OpenCVE Enrichment
Debian DSA