Impact
The flaw is a side‑channel leakage in Chrome’s WebAudio component that, when triggered by a malicious page, exposes information across origin boundaries. It is an information‑exposure issue (CWE‑1300) and a timing side‑channel (CWE‑203), which together allow a remote attacker to infer data otherwise protected by same‑origin policy.
Affected Systems
All desktop Google Chrome builds compiled from the Chromium source tree before version 150.0.7871.47 are vulnerable. No other browsers or vendors are affected.
Risk and Exploitability
The CVSS score of 6.5 signals medium risk, while the EPSS score of < 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that an attacker must persuade a user to load a crafted page in a vulnerable Chrome instance; user interaction is required. The flaw does not enable code execution or denial of service, but it does compromise confidentiality across origin boundaries.
OpenCVE Enrichment
Debian DLA
Debian DSA