Impact
A race condition in the WebRTC component of Google Chrome on Windows allows a malicious web page to trigger a flaw that causes the browser to read and expose data belonging to a different origin. This vulnerability represents a confidentiality breach and is classified as CWE-362.
Affected Systems
Google Chrome users on Windows with a version earlier than 150.0.7871.47 are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of < 1% suggests a very low but non-zero exploitation likelihood. The vulnerability is not listed in CISA KEV. Exploitation requires a victim to visit a crafted web page that triggers the WebRTC race condition during normal browser activity, allowing the attacker to read cross-origin data from the browser’s memory. While feasible, the low EPSS indicates limited real-world spread.
OpenCVE Enrichment
Debian DLA
Debian DSA