Impact
The flaw is an insufficient validation of untrusted input within Blink in Google Chrome before version 150.0.7871.47. This weakness, identified as CWE-20, enables a remote attacker to bypass the browser's same‑origin policy by serving a specially crafted HTML page. The primary impact is that the policy, which isolates web content from different origins, can be circumvented, potentially undermining the browser's security guarantees.
Affected Systems
The vulnerability affects Google Chrome browsers running any version earlier than 150.0.7871.47. No other products or vendors are known to be impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3 and an EPSS score of less than 1%, indicating low severity and a low likelihood of exploitation, and it is not listed in CISA KEV. Exploitation would involve a victim loading a specially crafted HTML page, a common scenario in phishing or drive‑by attacks. The likely attack vector is a web page hosted on an attacker‑controlled site that a user visits. This flaw bypasses the browser’s same‑origin policy, potentially undermining the isolation between web origins.
OpenCVE Enrichment
Debian DLA
Debian DSA