Impact
Incorrect authorization in an internal Actor component of Google Chrome versions prior to 152.0.7977.75 enables a remote attacker who has already compromised the renderer process to bypass the browser’s web origin policy via a specially crafted HTML page. The CWE-863 weakness means the system fails to enforce proper permissions, allowing access to web resources that should be protected.
Affected Systems
The issue affects Google Chrome for desktop. Any installation of Chrome below version 152.0.7977.75 is vulnerable. The vulnerability is tied to the actor handling of renderer processes and is not limited to a specific platform variant.
Risk and Exploitability
The CVE lists EPSS as not available and it is not in CISA’s KEV catalog. The attack requires the attacker to first gain control of a renderer process, which is a high barrier and typically local or requires a separate exploit. Because the flaw is an authorization failure that permits origin policy violations, an attacker could read or manipulate data from other origins if they succeeded in injecting malicious content. The overall risk is moderate with a low CVSS score as reported by Chromium, but the real world exploitability remains limited without an initial renderer compromise.
OpenCVE Enrichment