Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 148.0.7778.96
A vulnerability in Google Chrome prior to version 148.0.7778.96 allows a remote attacker to bypass site isolation protections. This issue arises from insufficient validation of untrusted input in the Cross-Origin-Opener-Policy (COOP) header. An attacker who has compromised the renderer process can exploit this vulnerability by delivering a crafted HTML page.
Exploitation of this vulnerability could lead to a bypass of site isolation, potentially allowing for cross-origin attacks or data leakage between sites.
Users can update to Google Chrome version 148.0.7778.96 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.