Impact
Insufficient validation of untrusted input in Chrome’s Cast functionality, which reflects weak input validation (CWE‑20) and improper sanitization (CWE‑79), allows a remote attacker to extract cross‑origin data by serving a specially crafted HTML page. The flaw bypasses the browser’s same‑origin policy, permitting access to content from other domains.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 are affected. The vulnerability applies to all platforms supported by the stable channel of Chrome, as documented by Google’s security release notes.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity impact, while the EPSS score of less than 1% signals a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires a victim to visit a malicious web page that uses the Cast feature; the attacker can then read and exfiltrate cross‑origin data through the browser’s compromised input handling.
OpenCVE Enrichment
Debian DLA
Debian DSA