Impact
The vulnerability arises when DevTools does not properly validate untrusted input, allowing a remote attacker who has already compromised the renderer process to craft a malicious HTML page that leaks cross‑origin data. This flaw permits unauthorized disclosure of information that should be protected by the same‑origin policy, potentially exposing sensitive data such as session tokens, cookies, or local storage from another origin.
Affected Systems
Google Chrome browsers with versions earlier than 148.0.7778.96 are affected. The problem is fixed in the 148.0.7778.96 release, so any installation running a prior version is vulnerable.
Risk and Exploitability
EPSS is < 1%, indicating a low probability of exploitation, but it is not zero. The flaw is not listed in the CISA KEV catalog. Chromium rates the vulnerability as medium severity with a CVSS score of 3.1. The attack requires that the attacker already compromise the renderer process, which typically requires code execution in a web page or a malicious extension. No public exploit code is known, so the risk remains moderate yet it poses a serious threat in environments that render arbitrary web content.
OpenCVE Enrichment
Debian DSA