Impact
The flaw stems from an inappropriate implementation in the PerformanceAPIs of Google Chrome versions earlier than 150.0.7871.47. An attacker who crafts a malicious web page can cause the browser to expose data that belongs to a different origin, resulting in a cross‑origin data leak. The weakness is identified as CWE‑352.
Affected Systems
All users running Google Chrome versions older than 150.0.7871.47 are potentially affected. When a user opens a maliciously crafted web page, the flaw can expose cross‑origin data that the browser otherwise protects.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attackers only need to entice a user to visit a malicious web page; no additional privileges are required. While the probability of exploitation is low, the confidentiality impact warrants prompt patching.
OpenCVE Enrichment
Debian DLA
Debian DSA