Impact
An insufficient policy enforcement flaw in Chrome’s Prefetch mechanism allows a remote attacker to create a crafted HTML page that can read data from a different origin. The vulnerability permits the extraction of cross‑origin content such as cookies, local storage, or network responses, resulting in information disclosure. The flaw is classified as an information‑exposure weakness and aligns with improper policy enforcement defect types.
Affected Systems
Google Chrome users running any version prior to 151.0.7922.72 on Windows, macOS, or Linux are affected, as the security fix was incorporated in that release and earlier builds remain vulnerable.
Risk and Exploitability
The likely attack vector involves hosting a malicious web page that a victim visits; the attacker then leverages the Prefetch subsystem to read cross‑origin data that should be isolated. Based on the description, it is inferred that the attacker needs to deliver a crafted HTML page to the victim. The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, so current threat exposure is limited, though the high Chromium severity rating indicates that an effective exploit could cause significant information loss if it were used.
OpenCVE Enrichment
Debian DLA
Debian DSA