Impact
The vulnerability arises from insufficient validation of untrusted input in Chrome DevTools. A crafted page can induce a user to perform specific UI gestures within DevTools, causing the browser to expose cross‑origin data. This flaw, classified as CWE‑20, results in information disclosure but does not grant arbitrary code execution.
Affected Systems
All Google Chrome installations older than version 150.0.7871.47 on any platform are vulnerable. Users who view malicious pages that prompt them to interact with DevTools can experience the data leak.
Risk and Exploitability
The CVSS score of 4.3 categorizes the issue as Low severity, and the EPSS score of less than 1% coupled with its absence from the CISA KEV catalog suggests a low likelihood of widespread exploitation. The requirement for deliberate user interaction with the page’s UI gestures further mitigates immediate risk, although the potential for sensitive data exfiltration remains if users comply.
OpenCVE Enrichment
Debian DLA
Debian DSA