Impact
Out-of-bounds read in the V8 JavaScript engine of Google Chrome allows an attacker who delivers a malicious extension to read memory that belongs to the browser process. The flaw is a bounds-check failure (CWE-125) and enables unintended disclosure of data that may be sensitive, such as private browsing history or locally held credentials.
Affected Systems
Google Chrome versions earlier than 150.0.7871.46 on desktop channels are affected; the vulnerability resides in the V8 engine component of the browser.
Risk and Exploitability
The CVSS score of 5.9 labels this issue as medium severity, while the EPSS score of <1% and the fact that it is not listed in the CISA KEV catalog indicate a low current probability of widespread exploitation. Based on the description, it is inferred that the attacker’s likely method is to convince a user to install a malicious extension. The exploit requires no network access beyond the extension context and does not grant remote execution, limiting the impact to local data exposure on the victim’s machine.
OpenCVE Enrichment
Debian DLA
Debian DSA