Impact
The vulnerability lies in the Canvas implementation of Google Chrome versions older than 148.0.7778.96. A crafted HTML page can cause the browser to ignore the Same‑Origin Policy, allowing a remote attacker to read or manipulate content from another origin. This issue is a CWE-269 privilege escalation flaw, representing an authorization weakness that bypasses the intended same‑origin access controls. The attack enables the exfiltration of sensitive data, theft of authentication tokens, or unauthorized interactions with cross‑origin resources that a session should protect.
Affected Systems
All users operating Google Chrome on desktop, prior to version 148.0.7778.96, are affected. The flaw applies across the stable channel releases on all platforms supported by Chrome in that version range.
Risk and Exploitability
Chromium assigned a Medium severity to the issue, with a CVSS score of 6.3, and EPSS data is unavailable, making exploitation likelihood uncertain. The lack of a KEV listing indicates no widespread exploitation at present. Nonetheless, a user who visits a malicious site containing a crafted HTML page could be subjected to a Same‑Origin Policy bypass, potentially compromising confidentiality and integrity of web sessions.
OpenCVE Enrichment
Debian DSA