Impact
A flaw in the Canvas rendering subsystem of Google Chrome before version 150.0.7871.47 enables a remote attacker to bypass the browser’s same‑origin policy by serving a malicious web page that can read data from another domain, resulting in the exposure of sensitive information. The vulnerability is an instance of insufficient policy enforcement (CWE‑346).
Affected Systems
All desktop installations of Google Chrome running any version earlier than 150.0.7871.47 are affected; the issue has a CVSS score of 6.5, indicating moderate severity. The EPSS score is below 1 %, suggesting a very low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog.
Risk and Exploitability
An attacker would need to convince a user to load a specially crafted web page, either locally or remotely; no widespread exploitation has been reported. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of < 1 % suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA