Impact
Inadequate trust boundary handling in Google Chrome’s GetUserMedia API allowed a malicious renderer to read data from other origins through a crafted web page. The flaw lies in improper input validation (CWE‑20) and can lead to leakage of sensitive information to an attacker controlling the renderer process. The consequence is exposure of cross‑origin data, affecting confidentiality but not enabling arbitrary code execution.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 are affected. Any installation before the stable channel update containing 151.0.7922.72 may be vulnerable. The issue is confined to the renderer process that handles GetUserMedia calls.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact whereas the EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting no large‑scale exploitation has been observed. An attacker would need to first compromise the renderer process—for example through a malicious extension or another Chrome vulnerability—and then serve a crafted HTML page that uses GetUserMedia to read cross‑origin data. Because the attack requires both renderer compromise and a specially constructed page, the overall risk for typical users is low, yet it remains a concern for environments that run untrusted renderer processes.
OpenCVE Enrichment
Debian DLA
Debian DSA