Impact
The flaw in the password handling of Google Chrome before version 149.0.7827.53 permits a malicious web page to circumvent the browser’s same‑origin policy. An attacker can cause the browser to treat a request for a resource from a different origin as if it originated from the same origin, allowing the page to read data it normally could not access.
Affected Systems
Google Chrome browsers prior to 149.0.7827.53, including all builds on the stable channel that have not applied the latest update, are vulnerable. The issue applies across all operating system platforms supported by Chrome.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is below 1%, suggesting a low but non-zero likelihood of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Based on the description, the attacker can trick a user into visiting a crafted HTML page that interacts with Chrome’s password subsystem, deriving a same‑origin policy bypass without needing elevated privileges.
OpenCVE Enrichment
Debian DSA