Impact
Google Chrome fails to enforce policy on CSS requests, which a remote attacker can exploit to read cross‑origin data from a crafted HTML page. The attacker can obtain content that should remain private to the target origin, representing a data‑exposure vulnerability and a failure to enforce policy enforcement (CWE‑693). Additionally, the policy bypass (CWE‑346) allows the attacker to circumvent the intended same‑origin restrictions on CSS, enabling the leak.
Affected Systems
The vulnerability affects all Google Chrome builds older than 149.0.7827.53. Users running any earlier Chrome version are susceptible until they upgrade to the fixed release or later.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% shows a low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user to visit a malicious web page that serves specially crafted CSS, which can then be used by the attacker’s code to extract data from a different origin.
OpenCVE Enrichment
Debian DSA