Impact
Google Chrome versions earlier than 150.0.7871.47 contain insufficient policy enforcement in the extensions framework, a combination of improper authorization (CWE-284) and information exposure. The flaw allows a malicious extension, which a user must first install, to read data from web origins other than its own, resulting in cross‑origin information exposure. This does not provide code execution or system compromise.
Affected Systems
The vulnerability affects all installations of Google Chrome earlier than 150.0.7871.47, irrespective of operating system. Users who have not updated to the fixed version remain exposed.
Risk and Exploitability
Based on the description, it is inferred that the attack vector requires an attacker to first social engineer a user into installing a malicious Chrome extension. Chromium rates the issue with a CVSS score of 4.3, indicating medium severity, while the EPSS score is below 1%, signifying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely exploitation path involves social engineering, convincing a user to install a malicious extension that bypasses policy checks and reads cross‑origin data.
OpenCVE Enrichment
Debian DLA
Debian DSA