Impact
A side‑channel information‑leak Paint component can expose cross‑origin data through a crafted HTML page, allowing a malicious site to read data from other browsing contexts without elevated privileges. The vulnerability is classified as CWE‑1300.
Affected Systems
All users running Google Chrome versions older than 150.0.7871.47 on any the or extensions.
Risk and Exploitability
The likely attack vector is a malicious web page that a user visits, which activates the vulnerable paint routine. The CVSS score of 6.5 places it in the medium‑severity band, while the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA