Impact
A policy bypass in the handling of MHTML files in Google Chrome allows a remote attacker to craft a malicious MHTML document that can leak cross‑origin data. The vulnerability does not provide code execution or denial of service, but it exposes private data the user is authorized to view, and it is classified as Low severity.
Affected Systems
Google Chrome desktop versions prior to 151.0.7922.72 are affected. The fix has been incorporated into recent stable channel releases by Google.
Risk and Exploitability
The CVSS score of 4.3 indicates a low overall impact, and the EPSS score of < 1% suggests that current exploitation rates are minimal. Attackers could exploit this vulnerability by delivering a malicious MHTML file that the victim opens in Chrome, making the risk dependent on user interaction. The vulnerability is not listed in CISA KEV, and there are no known active exploits yet.
OpenCVE Enrichment
Debian DLA
Debian DSA