Impact
The flaw occurs in the authorization checks executed during navigation in Google Chrome. If an attacker can inject a specially crafted HTML page that is rendered through a compromised renderer process, the browser may allow data from a different origin to be accessed. This bypasses Chrome’s same‑origin policy, enabling an attacker to read or modify resources that belong to other origins and potentially steal sensitive information or aid further attacks. The weakness is classified as CWE‑346 and CWE‑863.
Affected Systems
Affected product is Google Chrome. Versions prior to 152.0.7977.75 are vulnerable. The issue is present in all channel releases of Chrome that match the version criteria, regardless of operating system or device type. Users should verify their Chrome version and upgrade to a patched release.
Risk and Exploitability
The CVSS score is 3.1, indicating a baseline medium risk. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability requires that the attacker already have a foothold in the renderer process, meaning a prior local or remote code execution step is necessary. Consequently, the attack surface is limited to scenarios where a malicious page can be loaded into the compromised renderer. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA