Impact
An attacker who has already compromised the renderer process of Chrome can use a crafted HTML page that exploits incorrect authorization in the WebAppInstalls component. This flaw allows the attacker to bypass Chrome’s site isolation, gaining permission to install or modify web applications on the local machine with the privileges of the compromised renderer. Because the vulnerability resides in the renderer, the attacker’s local privileges are typically confined to the user who ran Chrome, but the ability to install applications expands the attack surface for further malware installation or data exfiltration.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are affected. The vulnerability specifically impacts the WebAppInstalls feature in desktop builds of Chrome; the affected component is present in all mainstream operating systems that run the stable channel.
Risk and Exploitability
The flaw carries a medium severity rating. Exploitation requires the attacker to first compromise the renderer process—a process that is largely sandboxed, but can be achieved by social engineering such as phishing or malicious extensions. Once the Renderer is compromised, the attacker can craft a malicious HTML page to convince the user to load it, thereby bypassing site isolation. The CVSS score of 6.5 reflects functional impact and limited exploitation potential. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, so the likelihood of widespread exploitation is currently unknown, but the attack vector is feasible under the right conditions.
OpenCVE Enrichment
Debian DLA
Debian DSA