Impact
Insufficient enforcement in Google Chrome’s Network component before version 150.0.7871.47 permits a remote attacker to craft a malicious HTML page that bypasses the same‑origin policy. The flaw is classified as CWE‑346, indicating that the browser failed to enforce the origin check that should prevent cross‑origin read or write operations.
Affected Systems
Google Chrome browsers running a version earlier than 150.0.7871.47 are affected; no other products or versions have been documented as vulnerable.
Risk and Exploitability
The CVSS base score of 4.3 signals low severity, and the EPSS score of less than 1 % indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. No user interaction requirement is explicitly stated, but based on the description, it is inferred that the victim would need to load the crafted HTML page. Consequently, the overall risk remains low, limited to a potential violation of the same‑origin policy if the flaw is successfully exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA