Impact
The vulnerability resides in the navigation component of Google Chrome and allows an attacker who has already compromised a renderer process to leak information and bypass site isolation. The attacker can craft an HTML page that sources the leaked data from the renderer and use it to exfiltrate information or manipulate isolation boundaries, potentially exposing sensitive content to other sites. The weakness is identified as an information disclosure flaw (CWE‑200).
Affected Systems
Google Chrome is affected. No specific version range is provided in the announcement. It is inferred that the issue was corrected in build 153.0.8010.36 and later releases of the stable channel, as the description references that version as the boundary.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates a Medium severity, and the attack requires that the attacker already has control over a renderer process to exploit the flaw. Based on the description and absence of publicly disclosed exploits, it is inferred that no public exploit is known, so the risk of exploitation appears moderate. However, potential information leaks and isolation compromise would remain significant if the attacker can place a renderer under their control.
OpenCVE Enrichment
Debian DLA
Debian DSA