Impact
Insufficient input validation in Chrome’s DevTools before version 150.0.7871.47 enables a remote attacker to craft a malicious HTML page that forces a user to perform specific UI gestures. When the user follows these gestures, the page can trigger the DevTools interface to read data during the same browser session, resulting in confidentiality loss but not remote code execution. The weakness involves CWE‑20 input validation. Based on the description, the attacker likely requires social engineering and user interaction to achieve exploitation.
Affected Systems
All users running Google Chrome earlier than 150.0.7871.47 are affected. The flaw is specific to Chrome’s DevTools, and no other browsers are known to be impacted. It appears that all users of the affected Chrome versions are at risk; this inference is derived from the CNA vendor/product info and the generic references to Chrome.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, reflecting medium severity. Its EPSS score of less than 1 % indicates a very low likelihood of exploitation. The likely attack vector involves social engineering to persuade the user to perform the required UI gestures, limiting potential for widespread attacks. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA