Impact
An improper implementation of password handling in Google Chrome versions prior to 150.0.7871.47 enables a remote attacker to retrieve cross-origin data by serving a specially crafted HTML page. The flaw bypasses the same-origin policy and allows sensitive information such as stored passwords to be read from malicious web content. The weakness is classified under CWE-522, indicating sensitive data exposure and resulting in a loss of confidentiality for credentials and other browser data.
Affected Systems
Desktop deployments of Google Chrome released before 150.0.7871.47 on any supported operating system are vulnerable. Users with those versions encounter risk when accessing malicious web content that can exploit the password handling weakness.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is medium severity and the EPSS score of < 1% indicates a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The likely attack path is inferred to require a user to visit a malicious web page that contains the crafted HTML, after which the page can read cross-origin data from the browser. Although exploitation is not widespread, the impact of credential leakage is significant.
OpenCVE Enrichment
Debian DLA
Debian DSA