Impact
Out-of-bounds read in the V8 JavaScript engine of Google Chrome permits an attacker who delivers a malicious extension to read data residing in the browser process memory, potentially exposing sensitive information. The flaw is a bounds‑check failure (CWE‑125) that allows unintended disclosure through the extension context.
Affected Systems
Google Chrome versions before 150.0.7871.46 on all platforms are affected. The vulnerability resides in the V8 engine component included in the browser.
Risk and Exploitability
The CVSS score of 5.9 labels the issue as medium severity. The EPSS score of <1% and the absence from the CISA KEV catalog suggest a low current probability of exploitation. The attack vector requires the attacker to convince a user to install a malicious extension, which then can read portions of the browser’s memory. No remote code execution or full system compromise is implied by the description.
OpenCVE Enrichment
Debian DLA
Debian DSA