Impact
The CVE describes an insufficient validation of untrusted input in Chrome’s SiteIsolation implementation. A crafted HTML page can cause a renderer process that has already been compromised to skip isolation checks, thereby allowing the attacker to operate without the protections normally enforced by site isolation. This is an input validation weakness (CWE‑20) and a site isolation flaw (CWE‑1286).
Affected Systems
All Google Chrome releases older than 148.0.7778.96 are vulnerable. The issue is fixed in the 148.0.7778.96 patch referenced in the Chrome release notes.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% reflects an extremely low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker who has already achieved control over a renderer process and the delivery of a crafted HTML page, which imposes several prerequisites and reduces the likelihood of successful exploitation.
OpenCVE Enrichment
Debian DSA