Impact
Based on the description, it is inferred that insufficient validation of untrusted input in the Input component of Google Chrome allows a remote attacker who has already compromised the renderer process to supply a crafted HTML page that can read data from origins that the page should not normally be able to access. The weakness is exposed by CWE‑20 (Improper Input Validation) and CWE‑79 (Cross‑Site Scripting) and it can expose confidential information. The vulnerability is only exploitable if the attacker has first gained foothold within the renderer process or another compromise channel is available.
Affected Systems
Google Chrome before version 148.0.7778.179 on macOS, Linux, or Windows is affected. The flaw resides in the browser engine component that runs within the renderer process on all supported operating systems.
Risk and Exploitability
Based on the description, it is inferred that the CVSS score of 5.3 indicates medium severity. Exfiltration requires prior compromise of the renderer process, which may need an additional vulnerability or privileged access. The EPSS score of < 1% and lack of listing in CISA KEV suggest that public exploitation is unlikely at present. However, adversaries who can initially breach the renderer process can leverage this flaw to leak cross‑origin data.
OpenCVE Enrichment
Debian DSA