Impact
A weakness in Glic's handling of untrusted input in Google Chrome allowed a remote attacker who had already compromised the renderer process to extract confidential cross‑origin data via a specially crafted HTML page. This vulnerability could be exploited to read information only available to the renderer’s original origin, potentially exposing user credentials or sensitive content without modifying system files or bypassing authentication.
Affected Systems
Google Chrome browsers running any version older than 149.0.7827.53 are vulnerable. The flaw exists in the Glic component and affects the stable channel of the desktop product.
Risk and Exploitability
The vulnerability carries a medium severity rating as noted by Chromium. The attacker must gain control of the renderer process, which is a lateral move within Chrome’s multi‑process architecture. While the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the potential for data leakage makes it a non‑trivial risk especially in environments where privileged renderer processes can be compromised.
OpenCVE Enrichment