Impact
Google Chrome improperly processes MHTML content, enabling a remote attacker that convinces a user to perform certain UI gestures to leak data from a different origin. The flaw results in information disclosure rather than code execution. The effect is the unauthorized read of cross‑origin data exposed through a crafted HTML page. The weakness aligns with improper handling of data across origins.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. The vulnerability exists in the MHTML implementation and applies to the standard desktop releases of Chrome.
Risk and Exploitability
The CVSS score is 6.5 and the EPSS score is < 1%, indicating limited or unknown exploitation prevalence. The issue is not listed in the CISA KEV catalog. The attack requires a user to interact with a malicious page and perform specific UI gestures to trigger the leak, suggesting a moderate difficulty channel. While the Chromium severity is medium, the potential for cross‑origin data exposure represents a tangible confidentiality risk for affected users.
OpenCVE Enrichment
Debian DSA