Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 147.0.7727.55 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| chrome | cert_advisory | 90% | |
| microsoft | microsoft edge | cert_advisory | 90% |
Updated vendor to Microsoft and product to Edge, and marked exploit as available.
Updated severity to CRITICAL, added affected version 146.0.7680.178, and corrected exploit availability.
Initial creation