Impact
Insufficient enforcement of extension policy in Google Chrome versions older than 150.0.7871.47 allows a remote attacker who has already compromised the renderer process to craft an HTML page that can read cross‑origin data. The flaw effectively lets an extension bypass its intended access controls and leak sensitive information to the attacker, demonstrating broken access control (CWE‑346).
Affected Systems
The vulnerability affects the Google Chrome browser for all operating systems when installed at a version prior to 150.0.7871.47. Any user running an older build is potentially exposed if an attack can reach a compromised renderer process.
Risk and Exploitability
Exploitation requires a prior compromise of the renderer process, a non‑trivial condition that limits the attack surface. The CVSS score of 4.3 classifies the vulnerability as low severity, the EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, making widespread attacks unlikely. Once the renderer is compromised, the attacker can read any cross‑origin data presented to the extension, creating a confidentiality risk. Chromium classifies the severity as low rather than mass‑scale.
OpenCVE Enrichment
Debian DLA
Debian DSA