Impact
The vulnerability lies in the DevTools component of Google Chrome before version 149.0.7827.53. A malicious Chrome extension can forge a request that grants read access to the browser process's memory, potentially exposing tokens, passwords, or other sensitive data stored in memory. The weakness is an information disclosure flaw caused by insufficient isolation between DevTools memory‑read operations and extension code, combined with a lack of authentication for the operation.
Affected Systems
Users running any Google Chrome build earlier than 149.0.7827.53 are affected. The issue was fixed in Chrome 149.0.7827.53 and all subsequent releases.
Risk and Exploitability
The exploit requires a user to install a compromised extension, making it a user‑mediated attack vector. The CVSS score of 5.9 indicates a moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, further indicating limited real‑world exploitation. However, any user who trusts and installs such an extension could expose sensitive information to the attacker.
OpenCVE Enrichment
Debian DSA