Impact
Insufficient policy enforcement in the HTML-in-Canvas feature of Google Chrome before version 150.0.7871.125 allows a remote attacker to create a crafted HTML page that bypasses the browser’s same-origin policy. This flaw exploits a weakness in policy enforcement (CWE‑346) and effectively permits access to data or resources that should be restricted, exposing sensitive information or enabling other unauthorized actions.
Affected Systems
Google Chrome releases earlier than 150.0.7871.125 are vulnerable; any user or organization running those versions is at risk until the update is applied.
Risk and Exploitability
The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, the CVSS score of 6.5 reflects a medium severity, and the nature of a same-origin policy bypass means that a determined attacker, once they deliver a crafted HTML page to the victim, could compromise the confidentiality and integrity of data presented within the canvas context. The likely attack vector is remote delivery of the malicious page via a website or compromised site.
OpenCVE Enrichment
Debian DLA
Debian DSA