Impact
In Google Chrome prior to version 149.0.7827.53, a flaw in the Canvas implementation allows a crafted HTML page to bypass the browser's same‑origin policy, a missing authentication for privileged functions identified as CWE‑346. This enables a remote attacker to read or alter cross‑origin data and potentially expose sensitive information or facilitate further exploitation. Chromium rated the issue as Medium severity.
Affected Systems
Google Chrome browsers running any release older than 149.0.7827.53 are vulnerable. No further version granularity was disclosed in the advisory.
Risk and Exploitability
The vulnerability can be exploited from a malicious webpage, so the attack vector is client‑side. The CVSS score of 6.5 indicates medium severity, and the EPSS score of < 1% suggests a low exploitation probability; it is not listed in CISA KEV. Successful exploitation would allow the attacker to read or modify cross‑origin data, potentially enabling more advanced attacks. No public workaround exists, so a patch is required.
OpenCVE Enrichment
Debian DSA