Impact
Chrome on Windows before 150.0.7871.47 contains a type‑confusion bug in its Bluetooth handling that allows a malicious peripheral to be interpreted as an unexpected object type. This misinterpretation causes the browser to read memory regions that are normally private, enabling an attacker to harvest sensitive data from Chrome’s process memory. The damage can include passwords, tokens, or other secrets that the user holds while browsing.
Affected Systems
All Windows users running Google Chrome versions older than 150.0.7871.47 are affected. The only available fix is the update to 150.0.7871.47 and later releases.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the lack of an EPSS score and absence from the CISA KEV catalogue suggest no publicly available exploits as of now. The attack vector requires the attacker to be on the same local network segment and to have a malicious Bluetooth peripheral that can interact with Chrome. Consequently, the threat is confined to environments where untrusted Bluetooth devices can be introduced, but organizations that require strict data confidentiality should consider the vulnerability significant and remediate promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA