Impact
An improper CSS implementation in Google Chrome versions prior to 150.0.7871.47 allows a remote attacker to leak data from other origins through a crafted HTML page, resulting in a confidentiality loss for information that should be protected by the same‑origin policy. The weakness aligns with information exposure (CWE‑200).
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47 are affected.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The CVSS score of 6.5 denotes moderate risk. Based on the description, it is inferred that the attack vector may involve a malicious web page that serves a crafted HTML document to induce cross‑origin data leakage.
OpenCVE Enrichment
Debian DLA
Debian DSA