Impact
The vulnerability arises from an incorrect implementation in the V8 JavaScript engine that permits a remote attacker to circumvent the same‑origin policy when loading a specially crafted HTML page. This flaw, classified as CWE‑346, effectively lets the attacker read or manipulate resources across origins, potentially exposing confidential data or executing unauthorized code.
Affected Systems
Google Chrome versions before 150.0.7871.125 are affected. The issue exists on all operating systems where Chrome includes the vulnerable V8 build, and affects users who have not upgraded to the patched stable channel release.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. The EPSS score of < 1% indicates a very low risk of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to serve or lure a victim to a malicious HTML page, placing the attack vector in a web‑based context that depends on user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA