Impact
Insufficient policy enforcement in Google Chrome's StorageAccessAPI before build 150.0.7871.47 allows a crafted HTML page to invoke this API and read data stored by the user from other origins, effectively leaking sensitive information that is normally protected by cross‑origin restrictions. The weakness is classified as CWE‑284, a privilege‑or‑access‑control vulnerability.
Affected Systems
All desktop installations of Google Chrome older than build 150.0.7871.47 are affected; the vulnerability applies to any operating system where Chrome runs, as the defect lies in the browser itself, not the host OS a malicious site or open a specially crafted page can trigger the data leak.
Risk and Exploitability
The CVSS score of 6.5 denotes a moderate severity, while the EPSS score of less than 1 % indicates a very low likelihood of active exploitation. The vulnerability is not listed in CISA's KEV catalog, and no publicly known exploits or attacks have been reported. An attacker would only need to host a malicious HTML page that the user visits; the attack requires no elevated privileges or additional network access to read the cross‑origin data.
OpenCVE Enrichment
Debian DLA
Debian DSA