Impact
The vulnerability arises when DevTools does not properly validate untrusted input, allowing a remote attacker who has already compromised the renderer process to craft a malicious HTML page that leaks cross‑origin data. This flaw permits unauthorized disclosure of information that should be protected by the same‑origin policy, potentially exposing sensitive data such as session tokens, cookies, or local storage from another origin.
Affected Systems
Google Chrome browsers with versions earlier than 148.0.7778.96 are affected. The problem is fixed in the 148.0.7778.96 release, so any installation running a prior version is vulnerable.
Risk and Exploitability
EPSS data is not available and the flaw is not listed in the CISA KEV catalog. The Chromium security severity is rated medium; the CVSS score is 3.1. The attack requires the attacker to have already compromised the renderer process, which usually implies execution of code in a web page context or a malicious extension. Because no public exploit code is known, the risk is moderate but still serious for environments that allow arbitrary web content to be rendered.
OpenCVE Enrichment
Debian DSA