Impact
Incorrect authorization within the Isolated context in Google Chrome versions prior to 153.0.8010.36 enables a remote attacker to circumvent the browser’s site isolation feature. Bypassing site isolation can expose data from distinct websites, allowing cross‑site information leakage or credential theft. The weakness is categorized as CWE-551 and CWE-863, representing authorization and access‑control weaknesses.
Affected Systems
Google Chrome is impacted. Any Chrome installation older than version 153.0.8010.36 fails to enforce proper isolation between site processes. Users on the stable channel, as well as potentially beta or dev channels rolling those versions, are at risk until the update.
Risk and Exploitability
Internet browsers are widely deployed, and the vulnerability can be exploited via a crafted HTML page served over the network, requiring only that a user view the page. EPSS score is less than 1%, and the issue is not listed in CISA’s KEV catalog, but the severity rating of 6.5 and remote access nature mean that attackers could combine it with other exploits to gather sensitive data. The official remedy is to install the updated Chrome build 153.0.8010.36 or newer.
OpenCVE Enrichment
Debian DLA
Debian DSA