Impact
The vulnerability resides in Google Chrome’s Network component where untrusted input is insufficiently validated. An attacker who has already compromised the renderer process can serve a specially crafted HTML page to that process. This allows the attacker to access and leak cross‑origin data, effectively bypassing same‑origin restrictions and exposing sensitive information. The weakness is identified as CWE‑20, input validation.
Affected Systems
Google Chrome versions prior to 149.0.7827.115 are affected. Any installation of Chrome not upgraded beyond this release date is vulnerable.
Risk and Exploitability
Chromium labels the issue as High severity, but exploitation requires an attacker first to gain control of the renderer process. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread, automated exploitation. However, an active threat actor with a foothold can use this flaw to exfiltrate data from the victim’s environment, causing confidentiality compromise. The risk is mitigated only by applying the vendor’s patch or avoiding the compromised renderer state.
OpenCVE Enrichment