Impact
An insufficient policy enforcement in the ViewTransitions API of Google Chrome allows a remote attacker to leak cross‑origin data by loading a specially crafted HTML page. The flaw manifests as both CWE‑368 (Race Conditions) and CWE‑942 (URL‑based Unrestricted Read Access), and the Chromium security severity is rated high, indicating that sensitive information could be exposed that belongs to a different origin.
Affected Systems
Google Chrome versions prior to 148.0.7778.168 on all supported operating systems are impacted. The flaw is tied to the ViewTransitions feature, which is enabled by default in these releases.
Risk and Exploitability
The exploit requires no special privileges and is browser‑based, meaning a malicious website can include a crafted page to trigger the ViewTransitions policy bypass. The CVSS score is 4.3. The EPSS score is < 1 % (a very low but non‑zero likelihood of exploitation in the wild). The flaw is currently not listed in the CISA KEV catalog. Given the moderate severity rating and the remote nature of the attack vector, the risk to users is significant until the vulnerability is patched.
OpenCVE Enrichment
Debian DSA