Impact
This vulnerability is an instance of Improper Input Validation (CWE‑20) and Untrusted Data from Untrusted Source (CWE‑346). A remote attacker can construct a malicious HTML page that, when opened in Google Chrome, causes the browser’s Cast functionality to expose data from a different origin. The flaw is classified as Medium severity with a CVSS score of 4.3.
Affected Systems
The issue affects users of Google Chrome on any platform running the browser before version 151.0.7922.72. It does not impact other browsers or later versions of Chrome.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. Nonetheless, a malware delivery scenario that drives victims to a crafted page could allow an attacker to read cross‑origin data. The impact is limited to information disclosure and depends on the victim visiting a malicious page, but the potential damage to the user’s privacy could still be significant.
OpenCVE Enrichment
Debian DLA
Debian DSA