Impact
A flaw in Chrome's handling of CSS allowed a remote attacker to read data that should have been protected by same‑origin rules. The attack involves serving a specially crafted HTML page that exploits the CSS implementation to expose sensitive information, compromising confidentiality. This vulnerability is classified as CWE-346: Information Exposure through lack of origin‑checking, and CWE-352: Cross‑Site Request Forgery, reflecting the improper enforcement of same‑origin policies and cross‑site request dependencies.
Affected Systems
The issue affects Google Chrome browsers with versions earlier than 149.0.7827.53. Users running those releases are susceptible until a newer build is installed.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploits yet. The only prerequisite is having a crafted HTML page run in the target browser, so the attack vector is remote via a web page. The CVSS score of 4.3 is medium; the lack of evidence of exploitation suggests current risk is moderate.
OpenCVE Enrichment
Debian DSA