Impact
Missing authorization checks in the DataTransfer API allow a remote attacker who has compromised the renderer process to craft an HTML page that reads sensitive information such as clipboard contents or user input stored in DataTransfer objects. This flaw, classified as CWE-862, effectively bypasses Chrome’s intended privacy controls and can expose confidential data to the attacker.
Affected Systems
Google Chrome desktop users running any version prior to 155.0.8059.39, on any supported operating system, are vulnerable. The issue is limited to the stable channel of Chrome and does not affect beta or dev releases beyond that version threshold.
Risk and Exploitability
The vulnerability carries a medium severity score of 5.3 on the CVSS framework, and the EPSS score is not available. It is not listed in the CISA KEV catalog, indicating no documented public exploitation. An attacker would need to first gain control of a renderer process—most likely via a separate vulnerability such as cross-site scripting—then serve a malicious HTML page that abuses the unprotected DataTransfer API. While the exploitation path is non-trivial, the moderate CVSS rating and lack of known public exploits suggest a moderate risk to affected users.
OpenCVE Enrichment