Impact
An inappropriate implementation in the Media layer of Google Chrome before version 149.0.7827.53 allows a remote attacker to read data across origins by serving a specially crafted HTML page. This flaw does not require user interaction beyond visiting the malicious page and can expose confidential information that should be protected by same‑origin policy, thereby compromising the confidentiality of the victim’s data.
Affected Systems
All Google Chrome desktop browsers running any version earlier than 149.0.7827.53. The issue applies to all platforms that execute Chrome’s media components.
Risk and Exploitability
The vulnerability is rated as medium with a CVSS score of 6.5. The EPSS score indicates an exploitation probability of less than 1 %, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires only delivery of a crafted web page; no additional privileges are needed. The potential impact of leaking sensitive cross‑origin information makes the risk moderate but actionable by applying the available patch.
OpenCVE Enrichment
Debian DSA