Impact
A side‑channel flaw was found in the media handling component of Google Chrome that permits a remote attacker to leak data from a different origin. By loading a specially crafted HTML page, an attacker can extract content that should otherwise be protected by the same‑origin policy. The CWE classification is 1300 and 346, indicating information disclosure through subtle side‑channel effects and a potential failure in authentication or access verification. The Chromium project rates the overall severity as low because the attack requires no privileged access and is limited to information leakage rather than code execution or denial of service.
Affected Systems
Google Chrome browsers running any version earlier than 148.0.7778.96 are affected. The flaw does not exist in the 148.0.7778.96 release or later releases.
Risk and Exploitability
The danger level is moderate: while the issue leads only to data leakage, it can be exploited from any web page the user loads, making it viable for attackers who can host malicious content. The EPSS score is <1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of mass exploitation but keeping targeted attacks plausible. The CVSS score for this vulnerability is 3.1.
OpenCVE Enrichment
Debian DSA