Impact
Google Chrome’s SiteIsolation feature contained an incorrect authorization check that allowed a remote attacker who had already compromised a renderer process to bypass system access restrictions by loading a specially crafted HTML page. The flaw is an access control weakness identified as CWE‑863 and, while it permits the attacker to execute privileged operations beyond the sandboxed renderer’s boundaries.
Affected Systems
All desktop installations of Google Chrome with a version earlier than 153.0.8010.36, regardless of operating system, are affected. The vulnerability specifically impacts the stable channel and is limited to the Chrome desktop product.
Risk and Exploitability
The EPSS score is <1%, indicating a very low exploitation probability. The CVSS score of 6.5 reflects medium severity. The vulnerability is not listed in CISA’s KEV catalog, indicating a moderate overall risk. Exploitation requires that an attacker first gain access to a compromised renderer process, either through local or remote code execution within Chrome, and then deliver a crafted web page that triggers the broken authorization logic. Once these prerequisites are met, the attacker can elevate privileges within the browser, potentially leaking sensitive data or executing malicious code with elevated rights.
OpenCVE Enrichment
Debian DLA
Debian DSA