Impact
Missing authorization for navigation in Chrome allows a remote attacker who has already compromised the renderer process to bypass site isolation using a crafted HTML page. The flaw permits the renderer to elevate privileges within the browser, enabling access to data or resources that belong to other sites. Chromium rates this issue as medium severity, indicating that while it does not directly allow arbitrary code execution, it can undermine the browser's security boundary.
Affected Systems
Google Chrome versions earlier than 154.0.8037.57 are affected. The vulnerability is tied to the renderer process and any Chrome implementation that ships with the same navigation code prior to the 154.0.8037.57 release.
Risk and Exploitability
Because the exploit requires a compromise of the renderer process, the overall risk is moderate. An attacker would first need to deliver malware or otherwise gain code execution in the renderer before triggering the site‑isolation bypass. No data is available for EPSS, and the flaw is not listed in CISA's KEV catalog, suggesting that large‑scale exploitation has not been observed yet. The medium severity rating indicates that the vulnerability can undermine browser isolation but does not grant arbitrary code execution.
OpenCVE Enrichment
Debian DSA