Impact
A flaw in Google Chrome’s QUIC implementation before version 152.0.7977.65 allows a remote attacker to craft an HTML page that causes the browser to treat resources from a different origin as if they were from the same origin. This arbitrarily relaxes the same‑origin policy and can expose sensitive data or allow session hijacking, taking advantage of the CWE‑610 weakness.
Affected Systems
The vulnerability applies to Google Chrome browsers earlier than 152.0.7977.65. All users running that version are susceptible regardless of operating system.
Risk and Exploitability
Chromium rates this issue as Medium severity. The CVSS score is 4.3, indicating moderate impact. The EPSS score is <1%, implying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it by delivering a crafted HTML page over the internet; the attack requires user interaction but imposes no additional infrastructure. Given the moderate severity and low exploitation probability, the risk is moderate but still significant due to potential widespread data exposure.
OpenCVE Enrichment
Debian DLA
Debian DSA