Impact
Google Chrome’s Dawn rendering engine suffered an inappropriate implementation (CWE‑284) that allows a remote attacker to read potentially sensitive data from the browser’s process memory. By loading a carefully crafted HTML page, an attacker can obtain information that may include personally identifying or privileged data, thereby compromising confidentiality.
Affected Systems
Versions of Google Chrome prior to 150.0.7871.47 are vulnerable. Any user or system running Chrome from the stable channel before this patch is potentially affected; newer releases contain the fix.
Risk and Exploitability
The likely attack vector involves delivering a malicious HTML page to the victim’s browser via a web-based vector. The assigned CVSS score of 6.5 indicates medium severity. The EPSS score of 0.00229 signals a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning no confirmed public exploits. The flaw can be triggered remotely, but only when the victim visits or otherwise loads the crafted page in Chrome.
OpenCVE Enrichment
Debian DLA
Debian DSA