Impact
In a network component of Google Chrome, an inappropriate implementation enabled a remote attacker to retrieve data from other origins through a specially crafted HTML page. This flaw permits the exfiltration of sensitive cross‑origin information, violating the browser’s same‑origin policy. The vulnerability is classified as medium severity within Chromium’s internal security model and represents an information‑exposure weakness.
Affected Systems
The issue targets Google Chrome versions released before 149.0.7827.53. Only the desktop stable channel is affected; newer Chrome releases contain the fix.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates a medium severity risk. Because the flaw exploits a mis‑handled network request, a remote attacker can simply navigate a malicious webpage to the victim’s machine. Cookies, local storage, and other sensitive data accessible across origins can be leaked—this inference is drawn from the description, which does not explicitly detail the data types, potentially compromising user accounts and data. No privileged host or advanced attacker capability is required to exploit the vulnerability.
OpenCVE Enrichment
Debian DSA