Impact
An implementation flaw in Google Chrome’s DevTools, present before version 150.0.7871.47, allows a remote attacker, through a crafted web page, to coerce a user into executing a specific sequence of UI gestures that inadvertently expose cross‑origin data. The attacker can thus read information from origins not intended for the user’s context, resulting in an unprivileged information disclosure. This flaw is categorized under CWE-352.
Affected Systems
Versions of Google Chrome older than 150.0.7871.47 are vulnerable. No operating‑system restrictions were cited in the advisory.
Risk and Exploitability
The CVSS score of 3.1 classifies the issue as low severity, and an EPSS score of less than 1% suggests a very low likelihood of exploitation. Successful attacks require a victim to be presented with a malicious web page, open DevTools, and perform the gestures specified by the attacker, which significantly limits routine exploitation. The vulnerability is not listed in the CISA KEV catalog and therefore poses a low but non‑negligible risk.
OpenCVE Enrichment
Debian DLA
Debian DSA