Impact
The SiteIsolation feature, allowing a remote attacker who separates the web content of distinct origins, can be bypassed when an attacker gains control of the renderer process. By exploiting the missing authentication, the attacker can interact with privileged APIs, read data, or perform actions on behalf of other sites, potentially leading to data leakage or further compromise. This weakness is classified as CWE-862.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 on any channel are affected by the missing authorization check in SiteIsolation.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating a high severity. The vulnerability is listed with a Chromium severity of Medium. The EPSS score is <1%, indicating a very low exploitation probability. It is not listed in CISA’s KEV catalog. Attackers would first need to gain control over the renderer process, typically via a malicious web page or to break SiteIsolation. Without that initial compromise, the attack vector is limited, reducing the likelihood of widespread exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA