Impact
The vulnerability is an insufficient input validation flaw in the WebUI component of Google Chrome that permits a remote attacker who has already compromised the renderer process to extract cross‑origin data. The flaw allows retrieval of information from other domains that the renderer is allowed to access, resulting in unintended disclosure of sensitive data.
Affected Systems
Google Chrome versions prior to 149.0.7827.53, released through the stable channel, are affected. Users of the stable channel who have not yet updated are at risk. The issue is fixed in the 149.0.7827.53 update.
Risk and Exploitability
Although the CVE severity is labeled medium, there is no EPSS score available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires control over the renderer process, which typically comes from a separate vulnerability; therefore, the likelihood is moderate until a mitigated renderer process is compromised. Applying the latest update mitigates the risk immediately.
OpenCVE Enrichment