Impact
This vulnerability stems from incorrect authorization checks during navigation in Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass the browser's same‑origin policy by loading a specially crafted HTML page. The attacker can then read or modify resources that belong to other origins, potentially exposing sensitive data or enabling further compromise.
Affected Systems
Affected product is Google Chrome, all stable channel builds older than 152.0.7977.75. The vulnerability applies to the desktop browser only. Users running versions prior to this update are exposed. Chrome may be installed via default OEM channels or via manual installation.
Risk and Exploitability
The CVSS score is not provided; EPSS indicates no data, and the vulnerability is not listed in CISA KEV. Based on the description, the attack requires that the adversary already has compromised the renderer process, which typically implies a prior local or remote code execution step. Hence the risk is considered medium; exploitation is limited to systems where an attacker can inject a malicious page into the renderer. Users should pace update to mitigate.
OpenCVE Enrichment