Impact
Chrome before version 150.0.7871.47 contains an implementation flaw in CSS handling that lets a remote attacker construct a crafted HTML page to bypass the browser’s same‑origin policy. The resulting weakness can allow the attacker to read or modify content from another origin that normally would be protected, potentially leading to loss of confidentiality or integrity of web data.
Affected Systems
All users running Google Chrome versions older than 150.0.7871.47 are impacted; the vendor’s update to that version includes the fix for the flaw.
Risk and Exploitability
The CVSS score is 6.5 and the EPSS score is less than 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the delivery of a malicious HTML page to a victim through the web; no publicly available exploit is currently known, but the potential for cross‑origin data exfiltration or manipulation means remediation is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA