Impact
Insufficient data validation within Chrome’s DevTools allows a remote attacker to craft a malicious HTML page that encourages a user to perform specific UI gestures. When the user follows the instructions, the page can trigger the DevTools interface to read data from a cross‑origin origin, exposing confidential information without executing code. The weakness is an input validation flaw categorized as CWE‑20, resulting in an information disclosure impact.
Affected Systems
Google Chrome installations running any version older than 150.0.7871.47 are affected. The problem is confined to the DevTools component of Chrome; other browsers are not known to be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while an EPSS score of less than 1 % reflects a very low probability of exploitation. A social‐engineering scenario is required to persuade a user to perform the necessary gestures, limiting widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA