Impact
Type confusion in the CSS engine of Google Chrome before 150.0.7871.47 allows a remote attacker to craft an HTML page that causes the browser to read arbitrary bytes from its own process memory, potentially disclosing sensitive data. The flaw is identified as CWE-843, and Chromium lists it as low severity.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 are affected. The issue applies to all platforms where the Chrome browser runs, including desktop operating systems such as Windows, macOS, and Linux, because the vulnerability is tied to the Chrome rendering engine.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score is not publicly available. The vulnerability is cataloged as low severity by Chromium. Consequently, the likelihood of exploitation is currently uncertain, but the impact would be a confidentiality breach of information stored in the browser process. The advisory does not indicate that the flaw has been actively exploited in the wild.
OpenCVE Enrichment
Debian DLA
Debian DSA