Impact
Google Chrome for Windows prior to 150.0.7871.125 has insufficient validation of media input in the renderer process. This flaw, tied to CWE-125 and CWE-20, allows a remote attacker who has already compromised the renderer process to read potentially sensitive information from the renderer process memory. Chromium security reviewers consider the flaw high severity.
Affected Systems
The vulnerability affects Google Chrome browsers running on Windows operating systems that use versions earlier than 150.0.7871.125. The affected product is Chrome for Windows; no other vendors or platforms are mentioned.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as medium severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first gain control of the renderer process, as stated in the CVE description. Consequently, the overall risk remains moderate to low.
OpenCVE Enrichment
Debian DLA
Debian DSA