Impact
Google Chrome versions before 150.0.7871.47 contain an insufficient data validation flaw in the NetworkCache component. The flaw lets a crafted HTML page read cached cross‑origin responses, resulting in a confidentiality breach without code execution or privilege escalation.
Affected Systems
All installations of Chrome in the stable channel running a version older than 150.0.7871.47 are susceptible to the vulnerability. Based on the description, it is inferred that this includes all platforms, as no platform restriction is specified.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is a malicious or compromised web page that serves the crafted HTML payload to the victim browser.
OpenCVE Enrichment
Debian DLA
Debian DSA