Impact
The vulnerability in Google Chrome arises from an inappropriate CSS implementation that permits a remote attacker to leak cross‑origin data through a specially crafted HTML page. This weakness is classified as CWE‑200, an information‑exposure issue, and can lead to cross‑origin information disclosure that compromises the confidentiality of normally protected data.
Affected Systems
Google Chrome versions released before 150.0.7871.47 are affected. Users on the stable channel who have not installed the June 2026 update remain vulnerable. The flaw is present in all builds earlier than the specified version, regardless of operating system.
Risk and Exploitability
According to the CVSS score of 6.5, the vulnerability falls into the medium‑severity range. The EPSS score of less than 1% indicates a low historical exploitation likelihood, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that a malicious webpage served to a victim’s browser could trigger the leakage, making the attack vector likely a remote attacker controlling an HTML page that prompts the browser to process the vulnerable CSS. The impact constitutes a confidentiality breach of cross‑origin data.
OpenCVE Enrichment
Debian DLA
Debian DSA