Impact
Insufficient validation of untrusted input in the DevTools window of Google Chrome on Windows lets a remote attacker, who convinces a user to perform specific UI gestures, read potentially sensitive data from the browser’s process memory through a crafted HTML page. The flaw is tied to Input Validation weaknesses (CWE‑20). The attack requires user interaction with a malicious page that triggers devtools actions, so it is not a purely blind remote exploit but still permits disclosure of in‑memory information that could include credentials or other sensitive data.
Affected Systems
Google Chrome for Windows versions earlier than 150.0.7871.47 are affected. The vulnerability was present in all stable channel builds up to that version and has been fixed in subsequent releases.
Risk and Exploitability
Chromium rates the issue as Medium severity. The CVSS score is 5.3. The EPSS score is not available, so no estimate of exploit probability is provided. The vulnerability requires a malicious web page to lure a user into performing specific UI gestures in DevTools; thus it needs user interaction and is not a blind remote exploit. The information disclosed could include sensitive data stored in the browser’s memory, such as credentials or tokens.
OpenCVE Enrichment
Debian DLA
Debian DSA