Impact
An inappropriate implementation in WebAppInstalls in Google Chrome versions before 149.0.7827.53 allows a remote attacker who has already compromised the renderer process to bypass the same‑origin policy using a specially crafted HTML page. This flaw can enable the attacker to read or modify data from other origins, potentially leading to data theft or injection of malicious content. The vulnerability is categorized as CWE‑20, reflecting an improper input validation weakness.
Affected Systems
The affected product is Google Chrome. All releases prior to 149.0.7827.53 are vulnerable, including the stable channel versions listed in the community advisory links.
Risk and Exploitability
The exploit requires the attacker to first compromise the renderer process, a condition that typically occurs through malicious web content or drive‑by attacks. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. With a medium severity rating in Chromium’s internal scoring, the risk is significant, especially in environments where the same‑origin policy is relied upon for data integrity and confidentiality.
OpenCVE Enrichment