Impact
Insufficient validation of untrusted input in Google Chrome’s Federated Credential Management (FedCM) prior to version 148.0.7778.96 allowed a remote attacker to leak cross‑origin data via a crafted HTML page. The likely attack vector is a malicious web page that leverages FedCM’s insufficient input validation. This is a classic input validation flaw (CWE‑20) that can expose information across origins but does not provide direct code execution or denial‑of‑service capabilities.
Affected Systems
The flaw affects installations of Google Chrome on desktop platforms using FedCM, specifically all releases prior to Chrome 148.0.7778.96. Based on the description, it is inferred that any user who interacts with a malicious page that triggers FedCM will be at risk of data leakage across origin boundaries.
Risk and Exploitability
The CVE is classified with low severity. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, indicating that widespread exploitation is not documented. The likely attack vector is a malicious web page that exploits FedCM’s insufficient input validation, requiring user interaction to load the page. Successful exploitation exposes cross‑origin data to the attacker. While the potential impact is limited to data exposure, the lack of mitigations could enable attackers to harvest sensitive information from unsuspecting users.
OpenCVE Enrichment
Debian DSA