Impact
The flaw arises from insufficient validation of untrusted input in Chrome’s New Tab Page before version 149.0.7827.103, identified as CWE‑20 (Input Validation) and CWE‑346 (Unchecked Input or Improper Validation). It permits an attacker who has already compromised the renderer process to supply a crafted HTML page that causes the browser to expose cross‑origin data. This omission leads to a high‑severity confidentiality breach, allowing sensitive information from other origins to be leaked.
Affected Systems
Affected systems are all machines running Google Chrome prior to version 149.0.7827.103, across any supported operating system that uses the stable channel. Users of 149.0.7827.102 or earlier are potentially vulnerable.
Risk and Exploitability
The exploit requires the attacker to have already breached the isolated renderer process, typically through a separate vulnerability or a malicious extension. Because this prerequisite is non‑trivial, the likelihood of a real‑world attack remains uncertain. The EPSS score is less than 1%, indicating a low likelihood of exploitation. The vulnerability is not in KEV. The CVSS score of 3.1 indicates a low to moderate overall risk, although the confidentiality impact remains significant if the renderer process is compromised. Chromium security severity is High, indicating that if the conditions are met, the data leakage could be severe.
OpenCVE Enrichment
Debian DSA