Impact
An inappropriate implementation in the Media component of Google Chrome allows a remote attacker to leak data across origins by delivering a crafted HTML page. The vulnerability permits the attacker to read data that is normally protected by the same‑origin policy, potentially exposing sensitive user information such as files, playback data, or other media content that should remain confidential. The impact is a direct information disclosure rather than code execution.
Affected Systems
Google Chrome versions preceding 148.0.7778.96 are affected. Users running these builds, typically on the stable channel, are susceptible to the data‑leak attack. Upgrading to 148.0.7778.96 or later removes the flaw.
Risk and Exploitability
The CVSS score is 4.3, indicating a Medium severity rating. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a malicious webpage that a victim visits, which can then read and exfiltrate cross‑origin media data. While exploitation does not require elevated privileges, any user who navigates to the crafted page could be affected.
OpenCVE Enrichment
Debian DSA