Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 132.0.6834.83
A vulnerability in Google Chrome's Fenced Frames feature, present in versions prior to 132.0.6834.83, allowed remote attackers to access potentially sensitive information from a user's system through a specially crafted HTML page. This issue arose because the Fenced Frames implementation improperly validated URLs, enabling the loading of local file directories via HTTP or HTTPS.
Exploitation of this vulnerability could lead to unauthorized access to local file directories, potentially allowing attackers to read sensitive information from the user's system.
The vulnerability can be reproduced by enabling Fenced Frames on a server that is not restricted by the default URL validation. Once Fenced Frames is active, a crafted HTML file can be served that exploits the vulnerability by loading local file directories into the Fenced Frame, bypassing the intended URL scheme restrictions.
Users should update to Google Chrome version 132.0.6834.83 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.