Impact
In Google Chrome prior to version 149.0.7827.53, a flaw in the Canvas implementation allows a crafted HTML page to bypass the browser's same‑origin policy, enabling a remote attacker to read or alter cross‑origin data and potentially expose sensitive information or facilitate further exploitation. Chromium rated the issue as Medium severity.
Affected Systems
Google Chrome browsers running any release older than 149.0.7827.53 are vulnerable. No further version granularity was disclosed in the advisory.
Risk and Exploitability
The exploit can be carried out from a malicious web page, so the attack vector is client‑side. Although EPSS data is unavailable and the vulnerability is not listed in CISA KEV, the seriousness of a same‑origin policy violation makes it a high‑risk issue. Successful exploitation would grant read access to cross‑origin data and open downstream attack possibilities. No public workaround exists, requiring a patch to remediate the problem.
OpenCVE Enrichment