Impact
A flaw in the Network component of Google Chrome allows a remote attacker to read data from a different origin by serving a specially crafted HTML page. The inappropriate implementation bypasses normal same‑origin restrictions, which is aligned with CWE‑346. This results in exposure of sensitive information and a direct breach of confidentiality.
Affected Systems
Google Chrome browsers running versions earlier than 151.0.7922.72 on any supported operating system are susceptible. All installations that have not yet applied the July 2026 stable channel update contain the vulnerability.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Exploitation requires only a crafted web page and occurs remotely, which makes it feasible for attackers who can host or embed such content in a user's browsing session.
OpenCVE Enrichment
Debian DLA
Debian DSA