Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 149.0.7827.103
A vulnerability in Google Chrome's handling of video files on Linux and ChromeOS, prior to version 149.0.7827.103, allows remote attackers to leak cross-origin data. This issue arises from an uninitialized use in the codecs component, which could be exploited by crafting a specific video file.
Exploitation of this vulnerability could lead to unauthorized access to cross-origin data, potentially allowing attackers to bypass same-origin policies and access sensitive information from other origins.
Users can update to Google Chrome version 149.0.7827.103 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.