Impact
The vulnerability is an inappropriate implementation in DOMStorage that allowed a remote attacker to leak cross‑origin data via a crafted HTML page. This flaw can lead to confidentiality‑only impact, exposing data that should have been isolated between origins. The weakness is identified as CWE‑346.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 are affected. Users of the stable channel running any build before that revision are at risk. The issue applies to all platforms that ship the affected Chrome binary.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑severity issue, and the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through a remote attacker serving a malicious web page that includes JavaScript or HTML that accesses the DOMStorage API. An attacker could retrieve data stored by another origin if the storage interface is improperly sanitized.
OpenCVE Enrichment
Debian DLA
Debian DSA