Impact
The vulnerability allows an attacker who convinces a user to install a malicious extension to bypass the browser’s same‑origin policy, enabling the attacker to read or modify content from web origins that the user did not consent to. The weakness is classified as CWE‑20, an input validation issue.
Affected Systems
Google Chrome browsers built before the 149.0.7827.155 release are affected, across all desktop platforms supported by Chrome. The issue applies to every user who installs a malicious extension before upgrading to the patched version.
Risk and Exploitability
The CVSS score of 4.2 reflects moderate severity, while the EPSS score of less than 1% indicates a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must persuade a user to install the malicious extension, and the exploit can only be performed while the user is actively using Chrome. This limits practical risk to environments where users install third‑party extensions and the browser remains unpatched beyond 149.0.7827.155.
OpenCVE Enrichment