Impact
An inappropriate handling within Google Chrome’s Passwords component prior to build 149.0.7827.103 allows a remote attacker to leak data across origins when a specially crafted HTML page is loaded. The flaw is an information‑exposure weakness; when exploited it lets the attacker read data belonging to another site, thereby compromising confidentiality of protected information.
Affected Systems
Google Chrome browsers running the vulnerable Passwords subsystem. All desktop installations using a version older than 149.0.7827.103 are potentially affected. No specific operating system is indicated in the advisory.
Risk and Exploitability
The vulnerability can be triggered by a remote attacker capable of serving a malicious web page. The CVSS score of 4.3 indicates a moderate severity. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, which does not reduce the risk that an attacker deploying a crafted page can successfully read cross‑origin data.
OpenCVE Enrichment
Debian DSA