Impact
Google Chrome’s Password Manager contains an inappropriate implementation that allows a remote attacker to leak cross‑origin data through a crafted HTML page. When a victim visits such a page, the attacker can obtain credentials that the browser would normally autofill from a different domain, resulting in disclosure of sensitive login information.
Affected Systems
The flaw affects the Chrome browser on desktop operating systems. Versions prior to 149.0.7827.53 are known to be vulnerable, though the vulnerability may exist in other earlier releases as well.
Risk and Exploitability
The Chromium team rated this vulnerability as Medium severity. The exploit is remote and can be triggered simply by delivering a malicious web page to the victim with a Chrome installation that has the Password Manager enabled. No local privilege escalation is required and no special network configuration is necessary. EPSS information is unavailable and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment