Impact
This vulnerability is a side‑channel information leak in Chrome’s ResourceTiming API. Prior to Chrome version 146.0.7680.71, a malicious webpage could be crafted to extract timing data that reveals user activity on cross‑origin resources, effectively allowing a remote attacker to observe sensitive cross‑domain information.
Affected Systems
All Chrome releases predating 146.0.7680.71 on Windows, macOS and Linux are affected. The vulnerability is tied to the browser’s implementation of the ResourceTiming interface and is independent of the underlying operating system beyond the fact that Chrome runs on Windows, macOS, and Linux.
Risk and Exploitability
The CVSS score of 3.1 indicates a low overall severity, and the EPSS score of less than 1% reflects a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited current exploitation. The attack likely requires a victim to visit a malicious web page that can use the ResourceTiming API to read timing data of cross‑origin requests.
OpenCVE Enrichment
Debian DSA