Impact
An improper MHTML parsing path in Chrome before 148.0.7778.96 allows a browser‑side leak of data from foreign origins. A crafted MHTML file can cause the browser to display data belonging to another domain when a user opens the file and performs UI gestures, enabling an attacker to obtain cross‑origin information. This weakness is cataloged under CWE‑1021, CWE‑346, and CWE‑352, and its CVSS score is 3.1.
Affected Systems
Chrome versions earlier than 148.0.7778.96 on Windows, macOS, and Linux are affected. The update resolves the flaw across all supported desktop operating systems.
Risk and Exploitability
Exploitation requires that a user is tricked into opening a malicious MHTML file that includes certain UI gestures. The EPSS score is under 1%, indicating low likelihood of widespread exploitation. This low‑severity vulnerability is not listed in CISA KEV catalog.
OpenCVE Enrichment
Debian DSA