Impact
Inappropriate handling of CSS in Google Chrome allowed a remote attacker to craft an HTML page that caused the browser to leak data from other web origins. This flaw, identified as CWE‑346, represents an external control of system parameters that bypasses same‑origin restrictions. The attacker can disclose sensitive information that would normally be protected by the browser’s security model.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 on any supported platform are affected. The advisory does not list any additional vendor or product variants. Users of these releases are vulnerable if they load untrusted HTML content.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity vulnerability. Because the EPSS score is less than 1% and the issue is not listed in KEV, the expected exploitation frequency is low. The attack likely requires that a victim load a crafted HTML page in Chrome, with no other elevated privileges needed. The impact is purely information disclosure rather than code execution or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA