Description
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A recent flaw in Google Chrome’s Bluetooth implementation allows a malicious web page to trigger a memory read that can expose sensitive data from the browser process. The weakness stems from insufficient policy enforcement for Bluetooth operations, resulting in a classic access‑control failure (CWE‑284). In practice, an attacker can embed crafted HTML that, when viewed on a device with Bluetooth enabled, causes Chrome to leak portions of its memory. The disclosure is confined to confidentiality exposure; the browser’s integrity and availability are not directly compromised. The official CVSS score of 6.5 indicates moderate severity, but Chromium labels the vulnerability as low because it requires a sophisticated attack scenario.

Affected Systems

Vulnerable Chrome releases are all versions older than 150.0.7871.47. Any user running those releases on any operating system remains at risk if the browser is exposed to malicious web content while Bluetooth is active. The fix was introduced in Chrome 150.0.7871.47 and subsequent builds.

Risk and Exploitability

Exploitability is limited by the need for the victim to visit a crafted web page and have Bluetooth enabled at the time. While no publicly available exploit scripts or tools have been reported, the EPSS for this entry is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Its CVSS score of 6.5 suggests that if exploited, a moderate amount of information could be captured, potentially revealing user credentials or other private data stored in memory. Absent an active exploit, the risk remains primarily theoretical; however, the possibility of memory disclosure warrants timely update or mitigation.

Generated by OpenCVE AI on July 1, 2026 at 13:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later.
  • Disable Bluetooth functionality in Chrome settings or at the operating‑system level to remove the vulnerable code path.
  • Observe browser logs for anomalous memory reads and monitor for unusual webpage visits that may hint at future exploitation attempts.

Generated by OpenCVE AI on July 1, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Bluetooth Memory Leak Leading to Information Disclosure in Google Chrome

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Chrome Bluetooth Policy Enforcement Flaw Exposing Process Memory
Weaknesses CWE-200

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome Bluetooth Policy Enforcement Flaw Exposing Process Memory
Weaknesses CWE-200
CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:16:41.364Z

Reserved: 2026-06-29T23:11:28.837Z

Link: CVE-2026-14035

cve-icon Vulnrichment

Updated: 2026-07-01T01:10:31.196Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T14:00:06Z

Weaknesses