Impact
The vulnerability is an inappropriate implementation in Google Chrome's Password Manager that enables a remote attacker to leak cross‑origin data when a user visits a specially crafted HTML page. The weakness allows the password management component to expose data that belongs to one origin to a different origin, compromising the confidentiality of that data between sites.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. All desktop builds of Chrome before this version, across operating systems, are impacted because the Password Manager component is part of the common browser binary.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score is less than 1%, signaling a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation has been confirmed. The likely attack vector is remote: an attacker can host a malicious website that loads a crafted HTML page, causing the vulnerable Password Manager to disclose cross‑origin data. No additional prerequisites are stated, so the threat can be realized as long as the vulnerable Chrome version is installed and a user views such a page.
OpenCVE Enrichment
Debian DSA