Google Chrome Fenced Frames Information Disclosure Vulnerability

Vulnerability

A vulnerability in Google Chrome's Fenced Frames feature, present in versions prior to 132.0.6834.83, allowed remote attackers to access potentially sensitive information from a user's system through a specially crafted HTML page. This issue arose because the Fenced Frames implementation improperly validated URLs, enabling the loading of local file directories via HTTP or HTTPS.

Impact

Exploitation of this vulnerability could lead to unauthorized access to local file directories, potentially allowing attackers to read sensitive information from the user's system.

Reproduction

The vulnerability can be reproduced by enabling Fenced Frames on a server that is not restricted by the default URL validation. Once Fenced Frames is active, a crafted HTML file can be served that exploits the vulnerability by loading local file directories into the Fenced Frame, bypassing the intended URL scheme restrictions.

Remediation

Users should update to Google Chrome version 132.0.6834.83 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
5.8
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.