Impact
The flaw is an inappropriate implementation in Chrome’s Media Router that allows a remote attacker to bypass the same‑origin policy by loading a specially crafted HTML page. The vulnerability is classified as CWE‑346, broken access control, and permits an attacker to read or execute data that should be confined to the browser’s origin sandbox, potentially exposing sensitive information or enabling further exploitation.
Affected Systems
Affected systems are Google Chrome browsers on desktop platforms running a version earlier than 151.0.7922.72. The vulnerability exists in the stable channel releases; users should verify that their build is older than this version and plan to upgrade.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of recent exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deploy a malicious HTML page and persuade a user to open it; once the Media Router processes the request, the same‑origin restrictions are bypassed. The attack vector is a web‑content vector, requiring no elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA