Impact
The Media component in Google Chrome before version 149.0.7827.53 contains an improper data‑handling path that can be triggered by a specially crafted HTML page. An attacker can cause the browser to expose data from a different origin, violating the same‑origin policy and leading to confidential information leakage. This flaw is an instance of a cross‑origin data leakage weakness (CWE‑352) and an improper memory handling vulnerability (CWE‑940).
Affected Systems
All desktop installations of Google Chrome running a version older than 149.0.7827.53 are vulnerable. The issue originates in the media handling subsystem of the browser binary, regardless of the operating system or user profile.
Risk and Exploitability
An attacker can remotely deliver the malicious HTML page to the victim’s device by simply visiting a compromised site. The vulnerability is listed with a CVSS score of 6.5; the EPSS score is below 1%, and the flaw is not included in CISA’s KEV catalog. While massive exploitation is unlikely at present, the confidentiality impact justify timely remediation.
OpenCVE Enrichment
Debian DSA