Impact
A missing authorization check in the media subsystem of Google Chrome on Windows permits a remote attacker who has already compromised the renderer process to read sensitive information through a specially crafted web page. The flaw is an authorization weakness that allows confidential data to be accessed without proper permission checks.
Affected Systems
Google Chrome running on Windows, specifically all releases prior to version 155.0.8059.39. The vulnerability manifests only before the update that addressed the missing authorization in the media component.
Risk and Exploitability
The flaw is not listed in the CISA KEV catalog and no EPSS score is available, suggesting it is not widely exploited at this time. Because exploitation requires an attacker to first compromise the renderer process—typically achieved via local code execution or a trusted site—this represents a lower severity risk in heavily sandboxed environments, but once the renderer is compromised, the attacker can freely access sensitive data through crafted pages. The impact is a confidentiality breach of data transmitted or displayed by Chrome's media features. The likely attack path involves a malicious web page that triggers the media component while the renderer process privileges remain high, bypassing normal authorization controls.
OpenCVE Enrichment