Impact
Google Chrome before version 150.0.7871.47 contains an insufficient data validation flaw in NetworkCache, classified as CWE‑20. A maliciously crafted HTML page can cause the browser to read cached responses from other origins, allowing a remote attacker to leak confidential data stored in the cache. The vulnerability does not enable code execution or privilege escalation; it merely exposes sensitive information that a user has already requested from another site.
Affected Systems
All installations of Google Chrome running a version older than 150.0.7871.47 on any platform are susceptible. The advisory for the stable channel and the absence of platform restrictions imply that every operating system that ships the affected Chrome version may be in scope.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score of < 1 %, or approximately 0.24 %, shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a malicious or compromised web page that delivers the crafted payload to a victim’s browser while the browser caches cross‑origin responses.
OpenCVE Enrichment
Debian DLA
Debian DSA