Impact
The vulnerability is introduced by an improper implementation of CSS parsing in Google Chrome versions prior to 150.0.7871.47. This flaw allows a remote attacker to cause the browser to expose data that originates from another domain, resulting in a cross‑origin information disclosure. The weakness is classified as an information‑exposure issue. The confirmed severity is moderate, with a CVSS score of 6.5 and a Chromium security rating of "Low". No publicly documented exploits exist at this time.
Affected Systems
The affected product is the Google Chrome desktop browser. Version numbers lower than 150.0.7871.47 are impacted, while Chrome 150.0.7871.47 and newer contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level for potential attackers. The EPSS probability is reported as less than 1 %, suggesting infrequent exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector involves a malicious web page that a user visits; remote attackers can deliver crafted CSS to trigger the flaw. No public exploits are documented, and the absence of evidence of active exploitation at this time suggests the vulnerability remains theoretical.
OpenCVE Enrichment
Debian DLA
Debian DSA