Impact
The flaw arises from insufficient validation of untrusted input in the Cast component of Google Chrome, mapped to CWE-20 and CWE-346. A crafted HTML page can trigger the defect, allowing a remote attacker to bypass the browser’s same‑origin policy and interact with web content from an unauthorized domain. The primary impact is that a malicious website can access or modify session data, steal credentials, or inject malicious scripts into a trusted page.
Affected Systems
All installations of Google Chrome older than version 149.0.7827.53 are affected. The vulnerability exists in the stable channel of the browser and applies to any device that has not yet applied the latest update from Google.
Risk and Exploitability
Chromium rates the issue as medium severity with a CVSS score of 6.5. The EPSS score indicates that the exploitation probability is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must deliver a crafted HTML page that a victim opens, so the attack vector is remote and requires user interaction. When enabled, the Cast functionality permits an attacker to break the same‑origin restriction, posing a moderate risk for web‑based attacks that rely on strict origin isolation.
OpenCVE Enrichment
Debian DSA