Impact
Insufficient validation of untrusted input while Chromium reads HTML content in ReadingMode on macOS allows a remote attacker who has already compromised the renderer process to serve a malicious page that bypasses the browser’s site isolation controls. This weakness is classified as CWE‑20 (Improper Input Validation) and CWE‑1289 (Improper Handling of Non‑Private Variables).
Affected Systems
Chrome on macOS versions earlier than 148.0.7778.168 are affected.
Risk and Exploitability
The CVSS score is 3.1, indicating low severity, and the EPSS score is below 1 %, reflecting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to first gain control of the renderer process; after that, the flaw permits bypassing site isolation, but the CVE description does not describe additional privileges or data access beyond that.
OpenCVE Enrichment
Debian DSA