Impact
The vulnerability arises from insufficient policy enforcement in FoldableAPIs, allowing a remote attacker who has compromised the renderer process to bypass Chrome’s same‑origin policy via a crafted HTML page. This breach lets the attacker read or modify resources that are normally isolated, potentially exposing confidential information or credentials. The weakness aligns with CWE‑20, reflecting improper input validation that permits policy violations.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected, regardless of operating system, because the flaw resides in a core browser API used across all platforms.
Risk and Exploitability
The CVSS score is 4.7, and the EPSS score is 0.00021 (approximately 0.021 %), indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so there is no known widespread exploitation. Exploitation still requires a prior compromise of the renderer process, often via malware or malicious content. Once inside that process, a crafted HTML page can invoke FoldableAPIs to bypass the same‑origin policy, potentially exposing or tampering with data, although the threat remains largely confined to the compromised renderer.
OpenCVE Enrichment