Impact
A security flaw in the Paint component of Google Chrome allows a remote attacker to craft an HTML page that bypasses the browser’s same‑origin policy. The insufficient policy enforcement means a page served from one origin can read or manipulate resources from a different origin that the user is not permitted to access. This creates confidentiality and integrity risks by potentially exposing sensitive data or enabling further malicious code execution. The weakness corresponds to CWE‑346 and is categorized with Chromium security severity Medium.
Affected Systems
The defect exists in Google Chrome on all platforms with versions older than 149.0.7827.53. Users running any pre‑149.0.7827.53 build are affected; Chrome updates after that revision contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score being less than 1% signals a low probability of exploitation. Based on the description, it is inferred that the attack vector involves a remote attacker delivering a crafted HTML page to a user. Because the Paint component did not correctly enforce same‑origin policy, the attacker can read or modify resources belonging to a different origin, exposing confidential data or enabling further malicious actions. The flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA