Impact
A flaw in Google Chrome Enterprise before version 150.0.7871.47 allows a remote attacker to read potentially sensitive data from the browser's process memory by loading a specially crafted HTML page. This leads to information disclosure and is identified as an access-control weakness (CWE-284). The result is the exposure of confidential data that is processed by Chrome, earning a high‑severity label from the Chromium security team.
Affected Systems
All installations of Google Chrome Enterprise running any Chrome version older than 150.0.7871.47 are affected. The issue does not apply to later releases that incorporate the fix.
Risk and Exploitability
The vulnerability can be triggered by a malicious or compromised web page that, giving a remote attacker the ability to read process memory. The 6.5 suggests a moderate‑to‑high risk of information disclosure, while the EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The flaw is currently not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA