Impact
PerformanceAPIs in Google Chrome prior to build 149.0.7827.53 enable a remote attacker, via a crafted HTML page, to read cross‑origin data that should be inaccessible. This side‑channel information leakage aligns with the weaknesses described by CWE‑1300, CWE‑203 and CWE‑346, granting unauthorized access to protected information and potentially exposing confidential user data. According to the Chromium security severity scale, the vulnerability is rated as low, though the confidentiality implications warrant attention.
Affected Systems
The affected product is Google Chrome. All builds prior to version 149.0.7827.53 that run the stable channel are vulnerable. No further version qualifiers or patch‑level details are provided beyond the indicated major build number.
Risk and Exploitability
The vulnerability can be exploited remotely by delivering a malicious web page that the victim opens or visits. No network authentication or elevated privileges are required beyond normal browser use. The EPSS score is < 1% and the CVSS score is 6.5. The issue is not listed in the CISA KEV catalog. The Chromium severity assessment lists it as low, suggesting limited threat, but the potential for cross‑origin data leakage can have significant confidentiality implications.
OpenCVE Enrichment
Debian DSA