Impact
Improper input validation in Chrome's SiteIsolation allows a remote attacker who has already compromised the renderer process to potentially execute arbitrary code outside the sandbox through a crafted HTML page, jeopardizing system confidentiality, integrity, and availability. The flaw is a classic input validation weakness (CWE-20).
Affected Systems
The vulnerability affects Google Chrome browsers running versions prior to 153.0.8010.36. Users of older releases are directly exposed until an update is applied.
Risk and Exploitability
Chromium grades this issue with a CVSS score of 8.3 (High), an EPSS score of <1%, and no KEV listing, indicating the exploitation risk is currently unknown but nonzero. The likely attack vector requires remote code that first compromises a renderer process, potentially via malicious web content; once inside, the attacker can escape the sandbox to run code with the renderer's privileges. No evidence suggests that the flaw is publicly exploitable at present, but the lack of a KEV listing means it may be in an early stage of exploitation or yet undisclosed. Organizations should anticipate a moderate threat level pending further evidence. They should treat the vulnerability as a high-priority patch candidate due to the potential for full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA