Impact
A flaw in Chrome’s CORS handling allows an attacker who has already subverted a renderer process to read data from unrelated origins using a specially crafted page. The vulnerability directly exposes cross‑origin information, making confidentiality the primary concern and mapping to CWE‑200.
Affected Systems
Google Chrome versions released before 152.0.7977.65 are vulnerable. The flaw affects the stable channel on desktop systems and requires that the attacker already has control over a renderer process.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV, and Chromium rates the issue as medium severity with a CVSS score of 3.1. Exploitation requires a prior compromise of the renderer process, which adds complexity and lowers the likelihood of a successful attack in the wild. Once renderer control is achieved, the attacker can freely leak sensitive cross‑origin data, but no public exploitation is documented as of now.
OpenCVE Enrichment
Debian DLA
Debian DSA