Impact
Google Chrome versions before 149.0.7827.53 contain an insufficient policy enforcement flaw in the Paint component that allows a remote attacker to construct a crafted HTML page to circumvent the browser’s same‑origin policy. This weakness permits the attacker to read or manipulate data from origins different from the current site, potentially leading to cross‑site data theft or execution of malicious scripts. The flaw maps to CWE‑346, indicating a failure to enforce the same‑origin policy correctly and a failure to validate the origin.
Affected Systems
Affected vendor is Google Chrome. All installations of Chrome that are older than version 149.0.7827.53 are vulnerable. No affected components or sub‑versions are listed beyond that baseline, so the attack surface covers any deployment of Chrome before the stated update.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score is < 1%, indicating a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation yet. The attack is feasible from any web page loaded in the vulnerable browser, and the attack vector is remote via a malicious web page, requiring only that the victim visits a crafted site; no local context is needed.
OpenCVE Enrichment
Debian DSA