Impact
A side‑channel leakage in the ComputePressure module of Google Chrome before 150.0.7871.47 is identified as CWE‑1300 and can compromise confidentiality of data visible in the victim’s browsing session.
Affected Systems
Google Chrome browsers with versions prior to 150.0.7871.47. Any user running an unpatched Chrome build is susceptible until the fix is applied.
Risk and Exploitability
The EPSS score of <1% indicates a very low probability of exploitation, and the CVSS score of 6.5 reflects medium severity. The vulnerability is not in the CISA KEV catalog. Attack requires the victim to view a malicious page or host content in an unpatched Chrome, which points to a cross‑origin communication trigger. The likely attack vector is opportunistic and limited to browsers where the leak can be triggered.
OpenCVE Enrichment
Debian DLA
Debian DSA