Impact
Google Chrome's Omnibox component contains an incorrect authorization check that lets a remote attacker who has already gained control of the renderer process extract sensitive information from a crafted HTML page. The flaw is classified as high severity by Chromium, reflecting the potential for significant data leakage. "Omnibox" refers to the combined address and search bar in Chrome, and any data accessed through it can include browsing history, credentials, or other private context to which the renderer has temporary access.
Affected Systems
Any desktop installation of Google Chrome using a version earlier than 155.0.8059.39 on the Stable channel is impacted. The issue applies to all platforms for which Chrome Stable is distributed, as the Omnibox component is a core part of the user interface across Windows, macOS, and Linux.
Risk and Exploitability
The vulnerability requires the attacker to have already compromised the renderer process, which typically implies a successful local compromise or a complex inter-process attack vector. The CVSS score of 5.3 indicates a medium severity level, and since EPSS data is unavailable and the issue has not been listed in CISA's KEV catalog, the probability of public exploitation is uncertain but the high impact of data disclosure warrants a high-priority response. The fix eliminates the authorization oversight, preventing any further leakage via crafted pages.
OpenCVE Enrichment