Impact
A flaw in Chrome’s password handling permits a remote attacker to obtain cross‑origin user data when a victim performs specific UI gestures on a maliciously crafted page. The defect stems from inadequate isolation of password dialogs, enabling the attacker to read sensitive information that should remain protected, thereby violating confidentiality (CWE‑200) and relying on implicit trust in page context (CWE‑346).
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 on all platforms supported by the browser are affected; no specific operating systems were listed in the advisory.
Risk and Exploitability
Exploitation requires the user to visit a crafted site and interact with the password prompt, conditions typically achieved via phishing or social engineering. The official CVSS score is 6.5, indicating medium severity, and the EPSS score is less than 1 %. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote user interaction with a web page, as the advisory does not explicitly detail the method. The limited EPSS score suggests low probability of widespread exploitation, yet the potential for data leakage warrants attention.
OpenCVE Enrichment
Debian DSA