Impact
This vulnerability is a confused deputy flaw in Google Chrome’s Contextual Tasks. A remote attacker who has already compromised a renderer process can trick the browser into treating a crafted HTML page as a privileged page, thereby bypassing the normal web origin policy. The effect is a privilege escalation that lets the attacker access resources that should be restricted to the privileged page, potentially leading to data theft or further compromise.
Affected Systems
The flaw affects Google Chrome versions before 155.0.8059.39. All users running these older builds are susceptible.
Risk and Exploitability
The exploit requires an attacker to first compromise a renderer process, which typically occurs through malicious web content or a prior vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The Chromium severity assessment is Medium, indicating that while the attack vector is remote, successful exploitation would grant the attacker elevated privileges within the browser context.
OpenCVE Enrichment