Impact
The flaw is an incorrect authorization check in Chrome’s Network component. It permits a remote attacker who has already compromised the renderer process to bypass the browser’s site isolation feature by loading a specially crafted HTML page. This bypass can enable the attacker to access data or interact with content from different browser contexts. The vulnerability is rated as high severity by Chromium.
Affected Systems
Google Chrome browsers running a version earlier than 153.0.8010.36 are affected. The flaw is present in all releases of Chrome before this update, which includes the stable, beta, and dev channels.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity.00178 (≈0.18%) and the issue is not listed in CISA KEV, indicating a very low probability of exploitation in the wild. The attack requires that the renderer process already be compromised, so it is an escalation after another vulnerability or social‑engineering step. If an attacker can reach the renderer, the crafted page can then escape site isolation. The high severity rating indicates that once the condition is met, the impact can be significant.
OpenCVE Enrichment
Debian DLA
Debian DSA