Impact
The vulnerability is a confused deputy flaw in the Omnibox that allows a remote attacker to craft network traffic and cause Chrome to ignore the web origin policy, enabling access to resources whose original protection is governed by same‑origin rules. The weakness is identified as CWE-441 and is assigned a medium severity by Chromium’s security team.
Affected Systems
Google Chrome desktop installations prior to version 155.0.8059.39 are affected, regardless of operating system.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalogue. The likely attack vector is network‑based, relying on the attacker’s ability to send crafted packets to a Chrome instance. Because the flaw permits a policy bypass without requiring local execution privileges, the risk to affected users remains moderate, warranting prompt mitigation.
OpenCVE Enrichment