Impact
In Chrome versions prior to 153.0.8010.52, a missing authorization check in the Storage component permits a malicious renderer that has already been subverted by a remote attacker to bypass site isolation when processing a malicious PDF file. The vulnerability can lead to the renderer accessing data that belongs to other browsing contexts, effectively escalating privileges within the browser.
Affected Systems
Google Chrome browsers with versions before 153.0.8010.52 are affected. The flaw is present in the Storage subsystem of the renderer process. Users running older Chrome releases on any operating system should be aware of this issue.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, and the EPSS score is below 1 %, implying a very low likelihood of mass exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to already compromise a renderer process and supply a specially crafted PDF that triggers the missing authorization check. Because of the narrow prerequisites and low exploitation probability, the risk profile is modest, but patching is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA