Impact
StorageAccessAPI of Google Chrome prior to version 150.0.7871.47 allows a remote attacker who has compromised the renderer process to bypass the browser's same‑origin policy via a crafted HTML page. This access‑control flaw (CWE‑284, CWE‑285) was rated with a CVSS score of 6.5.
Affected Systems
Google Chrome installations running a version earlier than 150.0.7871.47 are affected; the CVE data does not specify operating system coverage, but given Chrome's cross‑platform availability it is reasonable to infer that any OS is potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low exploitation probability at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to first compromise the renderer process, after which the bypass of same‑origin policy can be leveraged, but given current threat conditions the overall risk remains limited.
OpenCVE Enrichment
Debian DLA
Debian DSA