Impact
The vulnerability arises from an improper implementation of WebRTC in Google Chrome versions older than 149.0.7827.53, allowing an attacker with a privileged position on the same network to craft malicious traffic that extracts data from other origins. This flaw is an input validation weakness (CWE-20 and CWE-346) and results in unintended disclosure of private information, which could be used for further attacks.
Affected Systems
Google Chrome browsers running any version before 149.0.7827.53 are affected, including all stable channel releases prior to that build.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score is 5.9, indicating a medium severity. The vulnerability is not listed in CISA KEV. The medium Chromium security severity indicates that the flaw is not considered highly critical, yet an attacker only needs a privileged local network presence to exploit it. The lack of publicly disclosed exploit code suggests that exploitation may require custom traffic crafting, but the attack vector is realistic for compromised or rogue devices within an internal network.
OpenCVE Enrichment
Debian DSA