Impact
A crafted HTML page can exploit an inappropriate implementation of WebRTC in Google Chrome versions prior to 149.0.7827.53, allowing a remote attacker to read data from other origins. The vulnerability permits the leakage of potentially sensitive browser data, exposing confidential information without the user’s consent. The issue is classified as a medium severity cross‑origin data leakage, impacting confidentiality of user data.
Affected Systems
Google Chrome web browsers older than version 149.0.7827.53, regardless of operating system, are vulnerable. Users who have not yet updated to this or more recent builds need to update to close the flaw.
Risk and Exploitability
The vulnerability requires a remote attacker to host or inject a specially crafted page that the victim visits in their browser. The EPSS score of < 1% indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog, yet the ability to read cross‑origin content grants attackers a meaningful breach of confidentiality. Given the requirement for the victim to open a malicious page, the attack surface is narrow, but the potential impact remains significant for users who interact with web pages that could be expected to respect same‑origin policies.
OpenCVE Enrichment
Debian DSA