Impact
The vulnerability is an improper implementation in Chrome’s DataTransfer handling on macOS versions prior to 150.0.7871.47. By delivering a crafted HTML page that induces a user to perform specific UI gestures, a remote attacker can cause the browser to expose data that is normally restricted across origin boundaries, resulting in a cross‑origin data leak. The flaw resides in an access‑control weakness identified as CWE‑352 and does not provide a path for code execution or privilege escalation.
Affected Systems
Google Chrome running on macOS with any version earlier than 150.0.7871.47 is affected. Devices using these releases are at risk until they upgrade to the patched version or a later release that incorporates the fix.
Risk and Exploitability
The CVSS score of 3.1 denotes low severity, while the EPSS score of less than 1 % indicates a very small likelihood that this flaw will be actively exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user to interact with the malicious web page, meaning that the threat depends on social‑engineering tactics and the presence of a crafted UI. Given these constraints, the operational risk is modest yet it can lead to accidental disclosure of confidential data.
OpenCVE Enrichment
Debian DLA
Debian DSA