Impact
Insufficient policy enforcement in GuestView enables a remote attacker to leak cross‑origin data by hosting a crafted HTML page within the browser. This flaw allows the attacker to read data from a different origin, resulting in confidentiality loss but not executing code or compromising system integrity. The weakness is categorized as CWE‑346, an insecure direct object reference that bypasses intended access controls.
Affected Systems
This vulnerability affects Google Chrome on desktop platforms with versions prior to 151.0.7922.72. Users running any earlier stable build are potentially exposed. No specific operating system versions are indicated beyond the browser context.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to open a crafted page that contains GuestView components, meaning user interaction is necessary and no known public exploits exist. The attacker can gain access to sensitive cross‑origin data but cannot gain code execution or alter the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA