Impact
PerformanceAPIs in Google Chrome before build 149.0.7827.53 can be exploited by a remote attacker to leak cross‑origin data through a crafted HTML page. The vulnerability is a side‑channel information leak, allowing an attacker to read data that should be isolated by the same‑origin policy, potentially exposing confidential user information. This is a low‑severity flaw in Chrome’s Chromium engine according to the Chromium security severity scale.
Affected Systems
The affected product is Google Chrome. All builds prior to version 149.0.7827.53 that run the stable channel are vulnerable. No further version qualifiers or patch‑level details are provided beyond the indicated major build number.
Risk and Exploitability
The vulnerability can be exploited remotely by delivering a malicious web page that the victim opens or visits. No network authentication or elevated privileges are required beyond normal browser use. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. The Chromium severity assessment lists it as low, suggesting limited threat, but the potential for cross‑origin data leakage can have significant confidentiality implications.
OpenCVE Enrichment