Impact
An inappropriate implementation in Chrome’s Animation feature allows a remote attacker to craft an HTML page that can read data from a different origin, resulting in a confidentiality breach. The vulnerability is categorized as Information Exposure (CWE-200) and is linked to cross‑site request forgery weaknesses (CWE-352) inherent in the animation handling mechanism. If exploited, an attacker can expose sensitive user data or session information without requiring additional privileges or elevated access.
Affected Systems
Chrome browsers on Windows, macOS, and Linux are affected before version 145.0.7632.45. The issue applies to standard desktop installations across these operating systems.
Risk and Exploitability
With a CVSS score of 6.5, the threat is of medium severity. The EPSS score is below 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a maliciously crafted web page that a victim loads in Chrome, from which the attacker can retrieve cross‑origin data. No local privileges or code execution are required; the flaw is purely data‑exposure in the browser context.
OpenCVE Enrichment
Debian DSA