Impact
The vulnerability stems from insufficient validation of untrusted input within the Network component of Google Chrome. By exploiting this flaw, a remote attacker who has already compromised the renderer process can deliver a crafted HTML page that bypasses the same‑origin policy. The result is that the attacker can read data from other origins, potentially exfiltrating sensitive information. The weakness corresponds to CWE‑20 input validation."
Affected Systems
Chrome users running desktop versions prior to 149.0.7827.53 are affected. All stable‑channel builds below this revision are susceptible and should be upgraded to the specified or later patch level.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The Chromium severity rating for this issue is Medium. Exploitation requires that the attacker has already compromised the renderer process; without that foothold, the attack vector is limited. If the condition is met, the flaw can be abused to read cross‑origin resources, leading to confidentiality loss at the process level. With the current patch cycle, the likelihood of widespread exploitation remains moderate but cannot be dismissed.
OpenCVE Enrichment