Impact
The flaw is a confused deputy (CWE‑441) in Chrome's prerender component. When a renderer process is compromised, an attacker can create a crafted HTML page that the browser loads in a prerendered context. Because the browser trusts the renderer to enforce origin boundaries, the malicious prerendered page can violate the web origin policy and gain access to resources belonging to another origin. Based on the description, this could allow an attacker to read or manipulate data normally protected by the origin check, potentially leading to data theft or credential compromise; this inference is not directly stated in the CVE text.
Affected Systems
All stable channel releases of Google Chrome prior to 153.0.8010.36 contain the vulnerable prerender implementation. The issue is specific to the Chrome renderer process; therefore, any system running an affected Chrome version without the patch is potentially exposed.
Risk and Exploitability
The CVSS score is 3.1 and the EPSS score is <1%, indicating a low severity and low likelihood of exploitation. The vulnerability is not included in CISA’s KEV catalogue. An attacker would need to achieve remote code execution or exploit a cross‑site scripting flaw to compromise the renderer, then use the confused deputy to escape the origin boundary. Because the attack requires initial renderer compromise, the risk is moderate, but the impact of a successful bypass is high.
OpenCVE Enrichment
Debian DLA
Debian DSA