Impact
The flaw is a side‑channel leak in Chrome’s WebAudio component that, when triggered from a malicious web source, represents an information‑exposure weakness (CWE-1300) and a timing side‑channel (CWE-203).
Affected Systems
The vulnerability affects Google Chrome for desktop built from the Chromium source tree and present in all releases older than 150. No other vendors or product families are affected; the impact is limited to browsers from that codebase.
Risk and Exploitability
The CVSS score of 6.5 indicates medium risk, while the EPSS score of < 1 % reflects the low likelihood of exploitation at the time of this analysis. The flaw is not listed in CISA’s KEV catalog. An attacker would need to persuade a user to load a crafted page in a vulnerable Chrome instance. Based on the description, it is inferred that user interaction is required. The vulnerability does not enable code execution or denial of service, but it does compromise confidentiality across origin boundaries.
OpenCVE Enrichment
Debian DLA
Debian DSA