Impact
The flaw centers on the PerformanceAPIs implementation in Google Chrome versions earlier than 150.0.7871.47. A well‑crafted HTML document can cause the browser to expose data that belongs to a different origin, thereby leaking sensitive information to a remote attacker. The weakness is classified as CWE-352 and results in a confidentiality breach without requiring privileged execution.
Affected Systems
All instances of Google Chrome with a version older than 150.0.7871.47 are affected. The issue is confined to the PerformanceAPIs component, so any user who loads a maliciously crafted page while using those versions might trigger the data leak. The fix is incorporated in Chrome 150.0.7871.47 and newer releases.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity. EPSS suggests an exploitation probability of less than 1%, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires only that a user visit a malicious page; no special privileges or background infrastructure are needed. Although exploitation is unlikely, the potential confidentiality compromise warrants updating browsers promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA