Impact
Google Chrome’s printing functionality contains a flaw that does not adequately validate input provided by untrusted sources. This weakness allows a remote attacker who has already compromised the renderer process to supply a crafted HTML page that bypasses the browser’s site isolation safeguards. By doing so, the attacker can access data that is normally confined to separate site contexts, such as cookies, session tokens, and browsing history. Based on the description, it is inferred that the attacker could read or manipulate sensitive information from other tabs or sites.
Affected Systems
All users of Google Chrome running a version earlier than 148.0.7778.216, regardless of operating system, are affected. The problem exists in the Chrome stable channel before the 148.0.7778.216 update.
Risk and Exploitability
The vulnerability has a CVSS score of 5, indicating low severity, and its EPSS score is < 1%. It is not listed in the CISA KEV catalog. Exploitation requires a preexisting compromise of the renderer process, typically achieved by loading malicious content or exploiting another flaw. The likely attack vector is a malicious HTML page used during a printing operation. While the attack surface is limited to situations where an attacker can inject such content, the potential impact is significant due to the ability to break out of site isolation and read or influence protected data.
OpenCVE Enrichment