Impact
Google Chrome versions prior to 155.0.8059.39 suffer from a missing authorization check in the Animation component, allowing a remote attacker to craft a malicious HTML page that bypasses the browser’s origin policy. This flaw can enable the attacker to read or modify web content from a different origin, potentially exposing sensitive data or enabling further attacks. The weakness corresponds to CWE-862, reflecting an improper authorization flaw. The assigned severity is Medium as reported by Chromium’s security team.
Affected Systems
Google Chrome on any operating system, specifically all releases older than 155.0.8059.39.
Risk and Exploitability
The vulnerability is exploitable from a remote attacker that can deliver a crafted HTML page, such as via a compromised web site or phishing email. Although the EPSS score is not available, the flaw remains unlisted in the CISA KEV catalog, indicating it is not currently a widely known exploited vulnerability. Nevertheless, because the flaw permits origin policy bypass, the potential for malicious exploitation is significant, especially in environments with untrusted web content.
OpenCVE Enrichment