Impact
A flaw in Google Chrome’s spellcheck system allows a remote attacker who has already compromised the renderer process to read sensitive data from that process’s memory through a specially crafted HTML page. The vulnerability does not provide code execution or broader control, but it can expose user data or browser state that resides in memory. The weakness is a classic input validation error identified as CWE‑20.
Affected Systems
All releases of Google Chrome prior to version 150.0.7871.47 are affected. No other vendors or products known to be impacted, as the issue resides solely in Google’s Chromium‑based browser implementation.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score of less than 1% shows a very low probability of exploitation. However, the flaw requires a prior compromise of the renderer process, which could occur through separate vulnerabilities. If the renderer is compromised, an attacker can read memory contents via the crafted page, potentially leaking user information. The vulnerability is not listed in CISA’s KEV catalog, so the overall risk remains moderate, but patching is recommended to eliminate the leakage path.
OpenCVE Enrichment
Debian DLA
Debian DSA