Impact
The flaw is an input validation weakness in the IndexedDB implementation that permits a crafted HTML page to be processed by a renderer process that has been compromised. This bypasses the same‑origin policy, allowing the attacker to read or write cross‑origin data that would otherwise be protected. The weakness is categorized as CWE‑20 and can compromise confidentiality and integrity of user data.
Affected Systems
Google Chrome is the affected product. Versions prior to 149.0.7827.53 on desktop platforms are vulnerable; any user running the stable channel before that build is at risk.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. The Chromium advisory marks the severity as low. Because the flaw requires a compromised renderer process, the likely attack vector is a scenario where the attacker already has local access or malware that can tamper with the renderer, making public exploitation uncertain but still warranting patching as the fix is available.
OpenCVE Enrichment