Impact
A vulnerability in Chrome’s FindInPage input handling permits a remote attacker who has already compromised the renderer process to read data from a different web origin. The flaw is an input validation error – CWE‑20 – that can lead to a confidentiality violation when the renderer is already under attacker control. Because the exploit requires a prior compromise of the renderer, the attack surface is limited to environments where such a compromise is possible, but an attacker who succeeds can leak cross‑origin data.
Affected Systems
Google Chrome Desktop users running any version older than 152.0.7977.65 are affected. The issue appears in the stable channel that is shipped to regular users and depends on a local compromise of the renderer process to be exercised.
Risk and Exploitability
Chromium labels the flaw as Medium with a CVSS score of 3.1. The EPSS score is < 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The requirement for a renderer compromise makes the path more advanced; the flaw does not grant privilege escalation, denial of service, or remote code execution. The risk to a typical user is moderate, but organizations that enforce strict separation between web origins should treat it as a higher priority until a patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA