Impact
A flaw in Chrome’s navigation handling lets a remote attacker who has already compromised a renderer process read data belonging to other origins through a specially crafted HTML page. The vulnerability results in information disclosure, exposing data that should remain confidential to the attacking party.
Affected Systems
The affectation is limited to Google Chrome version 147.0.7727.54 and earlier. All operating systems that run Chrome—Windows, macOS, and Linux—are susceptible because the flaw resides in the Chrome engine itself, not in the underlying OS. Users on any platform running the affected Chrome build are at risk until the browser is upgraded.
Risk and Exploitability
The CVSS score of 4.3 categorizes the weakness as low severity, and the EPSS probability is below 1 %. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to already compromise the renderer process, which typically demands more advanced or privileged access, such as malware that can take control of the rendering context. Because of this prerequisite, the risk to a general user population remains modest, though organizations that rely on strict cross‑origin isolation should consider the threat more seriously.
OpenCVE Enrichment
Debian DSA