Impact
The vulnerability resides in the WebMCP component of Google Chrome; insufficient enforcement of policy checks allows a remote attacker to bypass the same‑origin policy by using a specially crafted HTML page. This flaw, identified as CWE‑346, permits the attacker to read or modify data that is normally restricted to a different origin, thereby compromising the confidentiality and integrity of web content.
Affected Systems
Google Chrome is the affected product. Versions earlier than 151.0.7922.72 are vulnerable; no other vendors or product variants are listed.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as medium severity, and the EPSS score of less than 1% indicates a very low probability of widespread exploitation at present. The vulnerability is not included in the CISA KEV catalog. Exploitation is likely to be achieved by hosting a malicious HTML page that targets the victim’s browser, leveraging the weak policy checks in WebMCP without requiring further access or privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA