Impact
An inappropriate implementation in Chrome’s Passwords module enables a remote attacker who has already compromised the renderer process to read sensitive data from process memory. This memory read is triggered by a crafted HTML page and could expose user credentials or other confidential information. The weakness is an information disclosure flaw, matching CWE‑200 and CWE‑825.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. The vulnerability exists in the Stable channel and likely in all channel builds before the fix. No other vendors or products are listed.
Risk and Exploitability
The vulnerability is classified as medium severity, with a CVSS score of 6.5. Exploitation requires the attacker to first gain control of the renderer process, which typically involves delivering a malicious web page under the user’s control. The EPSS score is less than 1 percent, and the flaw is not listed in the CISA KEV catalog. Although the overall risk is moderate, any successful renderer compromise could lead to leaking sensitive memory contents, and no public exploit has been noted.
OpenCVE Enrichment
Debian DSA