Impact
An input validation flaw in Chrome’s video codecs allows a renderer process that has been compromised to read data from another origin. The flaw, classified as CWE‑20, lets an attacker leak confidential information that the renderer can access, creating a confidentiality breach without affecting integrity or availability.
Affected Systems
Google Chrome browsers on desktop that are earlier than build 149.0.7827.53 are affected. The issue exists in the Renderer process that handles all video decoding. Windows, macOS, and Linux users running the stable channel before this build are potentially vulnerable.
Risk and Exploitability
The vulnerability has no published CVSS score or EPSS estimate, and it is not listed in the CISA KEV catalog. Exploitation requires that the attacker already controls the renderer process, typically via a prior code‑execution compromise. Therefore the flaw is not exploitable by an unauthenticated remote attacker but can be leveraged after the renderer has been subverted, representing a medium‑to‑high risk in environments where renderer processes can be compromised.
OpenCVE Enrichment