Impact
Type confusion in Chrome's XML parsing lets an attacker read arbitrary memory content from a running process when a specially crafted XML document is processed. This is a CWE‑843 flaw that can reveal sensitive data such as session tokens, passwords, or other confidential information stored in Chrome's memory. While it does not provide code execution, the disclosure of private data can lead to credential theft and privacy violations.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. Any installation of Chrome that has not been updated to at least 149.0.7827.53 remains vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as medium severity. The EPSS score is less than 1%, indicating a very low but non‑zero likelihood that the vulnerability will be actively exploited. An attacker would need to deliver or open a malicious XML file, which could be done through a web page that encourages the file to be downloaded, an email attachment, or an application that triggers Chrome to parse the doc. The vulnerability can be triggered remotely by any user who opens the crafted XML in Chrome, and the impact is confined to the privacy of that user’s data rather than to wider system compromise.
OpenCVE Enrichment
Debian DSA