Impact
The vulnerability lies in Chrome’s handling of extensions. Crafting a malicious HTML page can cause a Chrome extension to disclose data from a different origin, thereby violating data confidentiality. The flaw is an information‑disclosure weakness that allows a remote attacker to exfiltrate data cross‑origin.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. All users running these legacy builds are at risk; the issue is specific to the desktop stable channel.
Risk and Exploitability
This is a medium‑severity issue per Chromium. No EPSS data is available and Chrome is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker delivering a crafted HTML page that triggers data leakage through the extension. Exploitation requires the victim to visit the malicious page while the vulnerable extension is active. The impact is primarily confidentiality loss, with limited impact on integrity or availability.
OpenCVE Enrichment