Impact
The vulnerability is a side‑channel information leak in the Navigation component of Google Chrome prior to version 148.0.7778.168. An attacker can craft a web page that, when opened by a victim, causes the browser to reveal cross‑origin data that would normally be inaccessible to that page. This leakage allows the attacker to obtain sensitive content from other sites the user has visited, violating confidentiality for those sites. The weakness is classified as CWE‑1300 and is reported by Chromium as a security severity of medium.
Affected Systems
All installations of Google Chrome with a major release older than 148.0.7778.168 on Windows, macOS, and Linux are affected. Any user who has not upgraded to this or a later release remains vulnerable.
Risk and Exploitability
The likely attack vector is a remote web page that the victim visits; no elevated privileges are required. Based on the description, it is inferred that the attacker only needs to serve a crafted HTML page that performs a navigation operation to trigger the leak. The CVSS score is 4.3, indicating a low numerical severity, but Chromium’s internal assessment labels the issue as medium. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The web‑based nature and requirement for user interaction reduce but do not eliminate the risk of cross‑origin data leakage.
OpenCVE Enrichment
Debian DSA