Impact
An incorrect authorization check in the ORB component of Google Chrome before version 153.0.8010.52 permits a remote attacker to bypass the browser’s site isolation feature by delivering a crafted HTML page; the flaw, identified as CWE‑863, means the attacker can interact with resources that should be restricted by site isolation, potentially accessing data from other web origins.
Affected Systems
This vulnerability affects all Google Chrome browsers running versions earlier than 153.0.8010.52. The affected builds include the unpatched ORB component; no specific channel limitation is noted in the CVE data.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% points to a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a remote attacker delivering a malicious HTML page to a user with Chrome installed; user interaction by visiting or rendering the page is required to trigger the bypass. For most users, the overall risk remains low, but active exploitation could compromise data normally protected by site isolation.
OpenCVE Enrichment
Debian DLA
Debian DSA