Impact
The vulnerability is an sensitive information from the browser process. This weakness is an uninitialized variable error (CWE-457) and can result in loss of confidentiality.
Affected Systems
Versions of Google Chrome prior to 150.0.7871.46 are affected. Updating to 150.0.7871.46 or any newer release removes the vulnerability.
Risk and Exploitability
The flaw can be triggered entirely from a remote web page, meaning any site the victim visits could deliver malicious content. The CVSS score of 6.5 categorizes it as medium severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. Because it is not listedV catalog, no publicly known exploits are documented. Attackers a website to read uninitialized memory from the browser process, potentially exposing sensitive data from the process memory.
OpenCVE Enrichment
Debian DLA
Debian DSA