Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
The vulnerability consists of an information leakage side-channel vulnerability in the component responsible for handling forms (Forms) in Google Chrome. An attacker can prepare a malicious HTML page, which when visited by the victim causes unauthorized reading of data from other sources (cross-origin). The side-channel mechanism means that the leak occurs not through direct violation of access control mechanisms, but through observation of side effects of browser operation.
An attacker can gain access to sensitive cross-origin data, violating the confidentiality of information processed in other browser contexts. Data integrity is not directly threatened, however data disclosure may lead to further attacks.
Google Chrome should be updated to version 149.0.7827.53 or newer. The update is available through the browser's built-in update mechanism or on the manufacturer's website according to the reference chromereleases.googleblog.com.
Google Chrome in versions earlier than 149.0.7827.53 on Google Chrome operating systems, Apple macOS, Linux and Microsoft Windows.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApple macOS
OSAppleall versionsGoogle Chrome
APPGoogle< 149.0.7827.53Linux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP