Impact
An inappropriate handling of security-sensitive information in the Enterprise component of Google Chrome before version 150.0.7871.47 allows a remote attacker to read data from process memory. By luring a user to perform specific UI gestures on a crafted HTML page, the attacker can extract potentially private or confidential material. The weakness is identified as CWE‑203, which represents improper protection of information that may lead to disclosure.
Affected Systems
The vulnerability affects all Google Chrome browsers that use the Enterprise implementation and run any version earlier than 150.0.7871.47. Versions released after this patch are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The attack requires user interaction with a malicious web page and specific UI gestures, which means it depends on social engineering or user cooperation. Once the user engages the required gestures, information can leak from memory, but remote code execution is not possible.
OpenCVE Enrichment
Debian DLA
Debian DSA