Impact
An improper implementation of CSS parsing in earlier Google Chrome releases (<150.0.7871.47) is a CWE‑346 vulnerability that lets a remote attacker send a specially crafted HTML page that bypasses the browser’s same‑origin policy. Because the browser accepts malformed CSS from that page, the attacker can read or write data belonging to other origins, potentially enabling data theft or cross‑site scripting attacks. Chromium rates this flaw as high severity.
Affected Systems
All installations of Google Chrome on the stable channel running versions earlier than 150.0.7871.47 are affected. Users of newer versions are not vulnerable.
Risk and Exploitability
Based on the description, it is inferred that an attacker can host or send a malicious HTML page that triggers the flaw The CVSS score of 6.5 indicates moderate severity. The EPSS score is below 1%, indicating a very low probability of exploitation at present, yet the high severity rating and the ability to break the same‑origin boundary make this a valuable target. The problem is not yet listed in CISA’s KEV catalog, but the remote nature and broad user base create a substantive risk, especially if users are tricked into opening such content.
OpenCVE Enrichment
Debian DLA
Debian DSA