Impact
An unintended behavior in the DataTransfer object in Google Chrome versions before 149.0.7827.53 allows a remote attacker to leak cross‑origin data through a crafted HTML page. The flaw is a confidentiality issue and does not provide code execution or privilege escalation. The vulnerability is identified as CWE‑346. Chromium rates the severity as Medium.
Affected Systems
Any desktop installation of Google Chrome running a build older than 149.0.7827.53 is impacted. This includes Windows, macOS, and Linux deployments, which is inferred from Chrome’s widespread presence across those operating systems.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, indicating a low likelihood of exploitation. The CVSS score of 4.3 reflects medium severity. The likely attack vector is a malicious web page that causes the browser to read cross‑origin data through a crafted DataTransfer object, which is then transmitted to the attacker, compromising confidentiality without code execution or privilege escalation.
OpenCVE Enrichment
Debian DSA