Impact
An incorrect authorisation check in Chrome’s SiteIsolation feature allows a remote attacker who has already compromised the renderer process to bypass isolation boundaries by presenting a specially crafted file. By doing so, the attacker can access memory or resources belonging to other isolated sites, enabling data theft or further code execution within the browser context.
Affected Systems
Google Chrome users running any desktop channel version earlier than 153.0.8010.36 are affected. The issue is limited to the renderer process where SiteIsolation is enforced.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity, but the EPSS score of <1% and absence from CISA KEV indicate that exploitation is unlikely to be widespread. Exploitation still requires an already compromised renderer process and a social‑engineering step; if achieved, the attacker can bypass SiteIsolation, accessing data or executing code in other browser contexts.
OpenCVE Enrichment
Debian DLA
Debian DSA