Impact
Insufficient policy enforcement in the HTML‑in‑Canvas feature of Google Chrome before version 150.0.7871.125 allows a remote attacker to craft an HTML page that bypasses the browser’s same‑origin policy. This flaw effectively grants an attacker access to data or resources that should be protected, which could lead to theft of sensitive information or other unauthorized actions. The weakness represents an improper authorization flaw that undermines the fundamental security guarantees of web browsers.
Affected Systems
Google Chrome versions earlier than 150.0.7871.125 are affected. Any user or organization running these releases is vulnerable until a patch is applied.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known, commissioned exploit at this time. Nonetheless, the high severity rating and the nature of a same‑origin policy bypass mean that a determined attacker, once exploiting the flaw, could compromise the integrity of data viewed in the canvas context. The likely attack vector involves delivery of a crafted HTML page to the victim via a web page or compromised site.
OpenCVE Enrichment
Debian DLA
Debian DSA