Impact
A flaw in Chrome’s DevTools on Windows permits a remote attacker who persuades a user to perform specific UI gestures to read sensitive data from the browser’s memory. The weakness arises from insufficient validation of untrusted input (CWE‑20), allowing memory leakage that could expose personally identifying information or credentials if they are present in memory. Although Chromium rates the vulnerability as low severity, the potential for privacy compromise remains.
Affected Systems
Google Chrome on Windows, versions earlier than 150.0.7871.47, are impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. No EPSS score is available and the issue is not listed in the CISA KEV catalog, suggesting a low probability of widespread exploitation. The attack requires the victim to visit a specially crafted HTML page and perform guided UI gestures, so it relies on social engineering rather than a pure remote exploit. Once executed, the exploit can leak memory contents but does not provide full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA