Impact
The vulnerability permits a remote attacker to leak sensitive cross‑origin data through the StorageAccessAPI in Google Chrome. By delivering a crafted HTML page, an attacker can obtain information that the browser would normally keep segregated. This is an information‑disclosure flaw classified as CWE‑200. The exploit would not modify or destroy data, but it violates user confidentiality and can expose private information.
Affected Systems
Google Chrome browsers prior to version 152.0.7977.65 are affected. Users running any earlier stable channel version could be exposed to the data leak.
Risk and Exploitability
The exploit can be carried out remotely by hosting a malicious HTML page that a victim visits. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation at this time. The Chromium severity is marked low, and the CVSS score reflects a low impact. Nevertheless, the data exposed can be valuable, so the risk is low to moderate depending on the confidentiality of the compromised data.
OpenCVE Enrichment