Impact
An inappropriate implementation in the DevTools of Google Chrome before version 150.0.7871.47 allows a remote attacker to initiate a cross‑origin data leak by convincing a user to perform specific UI gestures while DevTools is open. The data exposed originates from another origin and can be read through a crafted HTML page, giving an attacker direct access to sensitive information. The weakness is represented by CWE‑352.
Affected Systems
All desktop builds of Google Chrome that are earlier than version 150.0.7871.47 are affected. The known affected product is Google Chrome; no specific operating systems were enumerated in the vulnerability data.
Risk and Exploitability
The CVSS score of 3.1 classifies the vulnerability as low severity, and the EPSS score of less than 1 % indicates a very low probability of exploitation. The exploit requires a user to be presented with a malicious page and to perform deliberate DevTools gestures, which limits the likelihood of success. The vulnerability is not listed in CISA’s KEV catalog and carries no known widespread exploitation evidence, making the overall risk low but not negligible.
OpenCVE Enrichment
Debian DLA
Debian DSA