Impact
Insufficient validation of untrusted input within Chrome’s DevTools before version 149.0.7827.53 enables a remote attacker who has already compromised the renderer process to bypass the same-origin policy through a crafted HTML page. The flaw is an input validation error (CWE‑20) and is classified by Chromium as Medium severity, potentially exposing local resources or facilitating lateral movement within the client.
Affected Systems
All users running any Google Chrome version older than 149.0.7827.53, regardless of operating system, are affected. The issue resides in the DevTools component of the browser and can be triggered when a malicious page is loaded through the compromised renderer.
Risk and Exploitability
Chromium rates the vulnerability as Medium severity. No EPSS score is available and it is not listed in the CISA KEV catalog. Exploitation requires the attacker first to compromise the renderer process—a condition that may arise from a separate vulnerability or social engineering. Once achieved, the attacker can serve a crafted HTML page that escalates to same-origin policy bypass. While an active exploit is not known, the potential impact warrants prompt remediation.
OpenCVE Enrichment