Impact
Insufficient policy enforcement in the Passwords module of Google Chrome prior to 150.0.7871.115 allows a remote attacker to bypass the Same‑Origin Policy with a crafted HTML page. The flaw is an input validation weakness identified as CWE‑20. The impact is that an attacker could gain access to resources normally protected by origin checks; the CVE text does not specify whether data can be read or modified, so the exact damage scope is not defined.
Affected Systems
All desktop builds of Google Chrome that run a version older than 150.0.7871.115 are affected. The CVE description does not explicitly state whether only the stable channel is impacted; the reference notes refer to Chrome updates prior to 150.0.7871.115. This includes Windows, macOS, and Linux platforms.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity from a CVSS perspective, although Chromium labels the issue as High, reflecting the policy‑bypass nature. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can deliver the malicious HTML through a hosted website or an embedded file that a user opens, but the description does not confirm whether additional local actions such as file‑system or network access are required. Based on the description, it is inferred that access to otherwise origin‑restricted content might be possible, though the extent is not explicitly described.
OpenCVE Enrichment
Debian DLA
Debian DSA