Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium)
The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html | release notes |
https://issues.chromium.org/issues/387583503 | permissions required |