Impact
The flaw is an input validation weakness in the IndexedDB implementation that permits a crafted HTML page to be processed by a renderer process that has been compromised. This bypasses the same‑origin policy, allowing the attacker to read or write cross‑origin data that would otherwise be protected. The weakness is categorized as CWE‑20 and CWE‑1173 and can compromise confidentiality and integrity of user data.
Affected Systems
Google Chrome is the affected product. Versions prior to 149.0.7827.53 on desktop platforms are vulnerable; any user running the stable channel before that build is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of < 1% suggests a very low exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Because the flaw requires a compromised renderer process, the likely attack vector is a scenario where the attacker already has local access or malware that can tamper with the renderer, making public exploitation uncertain but still warranting patching as the fix is available.
OpenCVE Enrichment
Debian DSA