Impact
The vulnerability allows a remote attacker to obtain cross‑origin data from the Payments subsystem in Chrome before version 155.0.8059.39. This results in leakage of potentially sensitive user data such as payment information and other content that was not intended to be exposed. The flaw is categorized as an information disclosure (CWE‑200) and could compromise user privacy and data integrity if the attacker has prior domain control.
Affected Systems
Google Chrome browsers with versions older than 155.0.8059.39 in the stable channel are affected. The issue was fixed in the subsequent releases as documented by Google. Users running the above versions should update to the latest stable release.
Risk and Exploitability
The attack vector is remote and triggered by serving a specially crafted HTML page to a victim's browser. The vulnerability was rated Medium severity by Chromium. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog, suggesting no active exploitation reports. Nonetheless, an attacker could exploit the flaw by hosting a malicious site that serves payment scripts, extracting information from other origins the victim visited. The absence of a public exploit does not eliminate risk, especially for organizations that run Chrome in environments with sensitive payment data.
OpenCVE Enrichment