Impact
An inappropriate implementation in the Media subsystem of Google Chrome versions older than 149.0.7827.53 allows a remote attacker to leak cross‑origin data through a specially crafted HTML page. This flaw enables the attacker to read data that should be isolated by the same‑origin policy, compromising the confidentiality of information displayed by other web origins. The weakness aligns with CWE‑200, Information Exposure.
Affected Systems
Google Chrome browsers running versions prior to 149.0.7827.53 are affected. The issue is present in the desktop stable channel and any product that incorporates the same media handling code up to that revision.
Risk and Exploitability
The vulnerability is exploitable by hosting a malicious web page that the victim visits; the attack requires the victim’s browser to load the crafted page. No known public exploit has been reported and the EPSS score is not available, implying a low or undetermined exploitation probability. It is not listed in the CISA KEV catalog. The Chromium security severity is labeled Medium, suggesting a moderate risk to confidentiality if a user visits a malicious page, but the impact is limited to data leakage rather than code execution or denial of service.
OpenCVE Enrichment