Impact
The vulnerability arises from insufficient validation of untrusted input in the WebAuthentication component of Google Chrome. A crafted HTML page can exploit this flaw to bypass the same‑origin policy if the attacker has already compromised the renderer process. The result is that the renderer can access resources from other origins that it should normally be barred from, potentially exposing confidential data or enabling further lateral movement.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. Users of the stable channel prior to the June 2026 security update need to upgrade to the patched release.
Risk and Exploitability
Chromium reports the issue with low severity. No public exploits are known and the EPSS score is not available. The flaw requires that the attacker already has control over the renderer, so it is not exploitable solely over the network. The vulnerability is not listed in the CISA KEV catalog, further indicating a low likelihood of widespread exploitation.
OpenCVE Enrichment