Impact
The vulnerability involves incorrect reference resolution in Chrome's DevTools. A remote attacker who has already compromised the renderer process can use a specially crafted HTML page to read sensitive data that would normally be protected. This flaw enables a confidentiality breach by exposing data visible in the DevTools environment for the compromised process.
Affected Systems
Google Chrome browsers for all platforms. The issue applies to versions prior to 155.0.8059.39; versions 155.0.8059.39 and later contain the fix.
Risk and Exploitability
The weakness relies on an attacker having control over the renderer process; therefore the attack vector is limited to scenarios where the renderer can be compromised locally or via other vulnerabilities. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower known exploitation likelihood. The CVSS score is 5.3, indicating moderate severity, but no EPSS data is available.
OpenCVE Enrichment