Impact
An incorrect implementation in the WebAppInstalls component of Google Chrome allows a remote attacker to bypass the browser's same‑origin policy by delivering a specially crafted HTML page. The flaw is identified as CWE‑346. This bypass enables an attacker to read or modify data from a different origin than intended, potentially exposing sensitive information or facilitating further attacks within the browser context.
Affected Systems
Chrome users running any version earlier than 150.0.7871.47 are affected. The vulnerability is confined to the browser; other system components remain unaffected.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity. The EPSS score of less than 1 % suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must convince a victim to load a malicious HTML page from a remote source to take advantage of the policy bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA