Impact
The flaw is an inappropriate implementation of the MHTML parser in Google Chrome that allows a remote attacker to read data from other origins if a user is tricked into performing specific UI gestures. The vulnerability results in the unauthorized disclosure of cross‑origin content, exposing potentially sensitive information. It involves an inadequately randomized component as described in CWE-1021 and a cross‑site request forgery condition as described in CWE-352.
Affected Systems
Google Chrome versions earlier than 148.0.7778.96 are affected. The issue is fixed in 148.0.7778.96 and later releases across all supported operating systems.
Risk and Exploitability
Exploitation requires delivery of a crafted MHTML file and convincing a user to interact with the browser’s UI. The CVSS score is 3.1, the EPSS score is < 1%, and the vulnerability is not currently listed in CISA’s KEV catalog, indicating a low current exploitation probability. However, because the attack vector relies on user interaction, it poses a moderate risk to users who may encounter forged MHTML files.
OpenCVE Enrichment
Debian DSA