Impact
Inappropriate implementation in Google Chrome’s Password Manager prior to version 149.0.7827.53 enables a remote attacker to leak cross‑origin data via a crafted HTML page. The flaw allows the attacker to read data that was previously inaccessible between origins, potentially exposing sensitive information stored locally by the browser.
Affected Systems
Google Chrome builds before 149.0.7827.53 on all platforms are affected; users running any earlier stable channel version remain susceptible until the issue is addressed.
Risk and Exploitability
Chromium’s security team rated the vulnerability as medium severity and the EPSS score is not available. The flaw can be exploited remotely by serving a malicious web page to a user’s browser, causing the leak of cross‑origin data. The vulnerability is not listed in CISA’s KEV catalog and no public exploits have been reported, yet its remote nature and the potential for data exposure justify prompt action.
OpenCVE Enrichment