Impact
A flaw in the Speech API within Google Chrome allows a remote attacker to craft an HTML page that bypasses the browser’s same‑origin policy. This represents a CWE‑346 vulnerability and permits the attacker to override the same‑origin restrictions that normally isolate resources, enabling access to content or data that would otherwise be restricted.
Affected Systems
The vulnerability exists in all Google Chrome desktop releases prior to version 150.0.7871.47. End users running any earlier build remain vulnerable until they update to the fixed release.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability that the vulnerability will be exploited, while the CVSS score of 9.6 marks it as highly impactful. The vulnerability is not listed in CISA KEV and no public exploits are cited in the CVE data. A remote attacker can host a malicious HTML page to trigger the bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA