Impact
A side‑channel flaw was found in the media handling component of Google Chrome that permits a remote attacker to leak data from a different origin. By loading a specially crafted HTML page, an attacker can extract content that should otherwise be protected by the same‑origin policy. The CWE classification is 1300, indicating information disclosure through subtle side‑channel effects. The Chromium project rates the overall severity as low because the attack requires no privileged access and is limited to information leakage rather than code execution or denial of service.
Affected Systems
Google Chrome browsers running any version earlier than 148.0.7778.96 are affected. The flaw does not exist in the 148.0.7778.96 release or later releases.
Risk and Exploitability
The danger level is moderate: while the issue leads only to data leakage, it can be exploited from any web page the user loads, making it viable for attackers who can host malicious content. With the EPSS score unavailable and the vulnerability absent from CISA’s Known Exploited Vulnerabilities catalog, the likelihood of mass exploitation is low, but targeted attacks remain plausible. The CVSS score for this vulnerability is 3.1.
OpenCVE Enrichment
Debian DSA