Impact
An insufficiently validated input vector in the Network module of Google Chrome allows a remote attacker, once having compromised the renderer process, to bypass the same‑origin policy. The flaw is a classic input validation weakness that can be exploited to gain unauthorized access to web page resources that would normally be restricted by browser security boundaries.
Affected Systems
Victims are users running Google Chrome prior to version 149.0.7827.53. The affected component is the renderer process within the browser. Any Chrome installation on which the renderer has been compromised can be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate risk. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV. Exploitation still requires the attacker to have already compromised the renderer process, which is a non‑trivial prerequisite. Without that condition, the flaw cannot be exploited, so the overall risk remains low to moderate depending on the likelihood of an earlier renderer compromise in the environment.
OpenCVE Enrichment
Debian DSA