Impact
Google Chrome versions before 149.0.7827.53 contain an insufficient policy enforcement flaw in the Paint component that allows a remote attacker to construct a crafted HTML page to circumvent the browser’s same‑origin policy. This weakness permits the attacker to read or manipulate data from origins different from the current site, potentially leading to cross‑site data theft or execution of malicious scripts. The flaw maps to CWE‑790, a failure to enforce the same‑origin policy correctly.
Affected Systems
Affected vendor is Google Chrome. All installations of Chrome that are older than version 149.0.7827.53 are vulnerable. No affected components or sub‑versions are listed beyond that baseline, so the attack surface covers any deployment of Chrome before the stated update.
Risk and Exploitability
The CVSS score is not provided, but the attack is feasible from any web page loaded in the vulnerable browser, making the risk a medium severity. The EPSS score is unavailable, indicating no public data on exploitation frequency. The vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation yet. The attack vector is remote via a malicious web page, requiring only that the victim visits a crafted site; no local context is needed.
OpenCVE Enrichment