Impact
A flaw in Chrome’s Cross‑Origin Resource Sharing implementation allows a malicious entity that has already compromised the browser’s renderer process to exfiltrate data from other origins through a crafted HTML page. The weakness results in the unintended transfer of cross‑origin information, thereby exposing sensitive content that should be restricted by the same‑origin policy. The vulnerability is catalogued as a missing authentication for a critical function (CWE‑346) and is rated low in severity (CVSS 3.1).
Affected Systems
Affected hosts are those running Google Chrome versions prior to 151.0.7922.72. Users should verify their current Chrome version and upgrade if it falls within the unsupported range.
Risk and Exploitability
The exploit requires that the attacker first achieve a foothold in the renderer process, a non‑trivial step that typically requires local or remote code execution within the browser. Even then, the damage is limited to leaking cross‑origin data, and the opportunity for further exploitation is constrained. EPSS lists a probability of less than 1 %, and the vulnerability is not present in the CISA KEV catalog. Consequently, the likelihood of widespread exploitation is low, though the potential impact to confidentiality is significant for compromised systems.
OpenCVE Enrichment
Debian DLA
Debian DSA