Impact
An inappropriate implementation in the passwords module of Google Chrome versions prior to 150.0.7871.47 permits a remote attacker to access cross‑origin data by serving a specially crafted HTML page. The flaw allows the attacker to read information normally protected by the same‑origin policy, such as stored credentials and other sensitive browser data. The weakness corresponds to CWE‑522, indicating improper handling of sensitive data.
Affected Systems
Any desktop installation of Google Chrome running a version older than 150.0.7871.47 is vulnerable. Users on those releases are at risk when they visit malicious web content that can exploit the password handling weakness.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating medium severity, and an EPSS score of < 1%, denoting a very low probability of observed exploitation. It is not listed in the CISA KEV catalog. Based on the description, a malicious HTML page opened or visited by a user could extract cross‑origin data, but detailed exploitation remains unpublicized.
OpenCVE Enrichment
Debian DLA
Debian DSA