Impact
Insufficient enforcement of the password policy in Chrome before 150.0.7871.47 allows a remote attacker who already compromised a renderer process to load a specially crafted HTML page that reads data from other origins, resulting in cross‑origin information disclosure. The flaw stems from improper access control (CWE‑284) in the password handling code.
Affected Systems
All Chrome installations prior to version 150.0.7871.47 on any operating system or release channel are vulnerable. Exploitation requires a renderer process to be compromised first, which can occur through other bugs, malicious extensions, or social engineering.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. With an EPSS score of less than 1 % the likelihood of exploitation is low, and it is not listed in the CISA KEV catalog. Exploitation necessitates that the attacker first gain a foothold in a renderer process; once achieved, a malicious HTML page can extract cross‑origin data via improper access control.
OpenCVE Enrichment
Debian DLA
Debian DSA