Impact
Insufficient enforcement of Chrome’s password policy allows an attacker who has compromised a renderer process to load a crafted HTML page that can read cross‑origin data. The defect is an instance of CWE‑284 (Improper Access Control), which enables unauthorized disclosure of sensitive information.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47, across any operating system or release channel (stable, beta, dev, or canary), are vulnerable. The vulnerability can be leveraged only when a renderer process has already been compromised, making systems that expose renderer components to untrusted content at risk.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is classified as medium severity. The EPSS score of less than 1 % indicates that widespread exploitation is currently unlikely. The issue is not listed in the CISA KEV catalog. From the description, it is inferred that exploitation requires an initial foothold in a renderer process—potentially achieved through another vulnerability, a malicious extension, or social engineering—after which a crafted HTML page can exfiltrate cross‑origin data.
OpenCVE Enrichment
Debian DLA
Debian DSA