Impact
A race condition within the WebRTC module of Google Chrome on Windows enables a malicious web page to trigger the flaw, causing the browser to read and expose data belonging to a different origin. This flaw represents a confidentiality breach and is classified as CWE-362.
Affected Systems
Google Chrome users running any Windows build with a version earlier than 150.0.7871.47 are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of < 1% suggests a very low but non-zero exploitation likelihood. The vulnerability is not listed in CISA KEV. Based on the description a malicious web page that a victim visits, which triggers the WebRTC race condition during normal browser activity, allows the attacker to capture cross‑origin data from the browser’s memory. While exploitation is possible, the low EPSS indicates limited real‑world spread.
OpenCVE Enrichment
Debian DLA
Debian DSA