Impact
Side‑channel information leakage in Chrome’s scroll handling enables a remote attacker to read data from another origin that should be protected by same‑origin rules. The flaw, classified as CWE‑1300, lets a crafted web page cause the browser’s scroll logic to leak cross‑origin data through observable side‑channel effects, resulting in a confidentiality breach of user information.
Affected Systems
All installations of the Google Chrome stable channel with a version older than 150.0.7871.47 on Windows, macOS, or Linux are affected, regardless of the underlying operating system.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate‑to‑high risk for information disclosure. With an EPSS probability of less than 1% and no listing in the CISA KEV catalog, widespread exploitation has not been reported. The likely attack vector is a malicious web page that the victim visits, requiring user interaction. The potential for cross‑origin data leakage warrants timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA