Impact
A flaw in the StreamsAPI of Google Chrome allows a crafted web page to expose privileged resources to scripts that normally would not have access. The vulnerability can be used by a remote attacker to bypass the web origin policy and reach privileged pages. The weakness is an improper exposure of protected resources, which could lead to information disclosure or unauthorized actions on behalf of the user.
Affected Systems
All users running Google Chrome versions earlier than 152.0.7977.65 are affected. The flaw resides in the StreamsAPI layer used by the browser to manage data streams, and only the listed Chrome builds contain the unpatched implementation.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating a medium severity risk, with an EPSS score of less than 1% and is not listed in the CISA KEV catalog. An attacker can exploit it by serving a specially crafted HTML file that triggers the vulnerable StreamsAPI, thereby bypassing origin restrictions. Because the attack vector is a web page loaded over the network, remote exploitation is feasible without local privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA