Impact
A behavioral flaw in the scrolling logic of Google Chrome versions before 155.0.8059.39 allows a malicious extension, installed by a remote attacker, to trick the browser into revealing data from a different origin. The vulnerability is an Information Disclosure weakness (CWE‑203) that enables an attacker to read protected information without proper authorization. The Chromium security review rates the issue as Medium severity because the impact is limited to data leakage within the context of an exploited extension and does not grant unrestricted code execution.
Affected Systems
All installations of Google Chrome whose major version is less than 155.0.8059.39, regardless of operating system, are susceptible. The flaw resides in the browser core, not tied to a specific platform or device. Users running older releases are therefore affected until they upgrade to a fixed version.
Risk and Exploitability
The attack can be carried out remotely by a threat actor who persuades a user to install a crafted extension. The exploit does not require privileged access or local compromise and leverages the browser’s cross-origin policy gaps. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploitation yet. Nevertheless, the Medium severity rating and the ease of delivery via an extension warrant timely remediation.
OpenCVE Enrichment