Impact
A recent flaw in Google Chrome’s Bluetooth implementation allows a malicious web page to trigger a memory read that can expose sensitive data from the browser process. The weakness stems from insufficient policy enforcement for Bluetooth operations, resulting in a classic access‑control failure (CWE‑284). In practice, an attacker can embed crafted HTML that, when viewed on a device with Bluetooth enabled, causes Chrome to leak portions of its memory. The disclosure is confined to confidentiality exposure; the browser’s integrity and availability are not directly compromised. The official CVSS score of 6.5 indicates moderate severity, but Chromium labels the vulnerability as low because it requires a sophisticated attack scenario.
Affected Systems
Vulnerable Chrome releases are all versions older than 150.0.7871.47. Any user running those releases on any operating system remains at risk if the browser is exposed to malicious web content while Bluetooth is active. The fix was introduced in Chrome 150.0.7871.47 and subsequent builds.
Risk and Exploitability
Exploitability is limited by the need for the victim to visit a crafted web page and have Bluetooth enabled at the time. While no publicly available exploit scripts or tools have been reported, the EPSS for this entry is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Its CVSS score of 6.5 suggests that if exploited, a moderate amount of information could be captured, potentially revealing user credentials or other private data stored in memory. Absent an active exploit, the risk remains primarily theoretical; however, the possibility of memory disclosure warrants timely update or mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA