Impact
Google Chrome on Windows contains a use‑after‑free flaw in the DataTransfer handling path. A local attacker can trigger the bug with a crafted HTML page and read arbitrary contents from the browser process memory, potentially exposing sensitive data. The vulnerability is classified as low severity by Chromium's internal rating and has a CVSS score of 5.5.
Affected Systems
The flaw affects Google Chrome on Windows versions prior to 151.0.7922.72. Users running any earlier build of the stable channel are at risk.
Risk and Exploitability
The attack vector is local and requires the attacker to deliver a malicious HTML document to the victim. Because the CVSS score is moderate and the EPSS score is less than 1%, exploitation is unlikely in the wild. The issue is not listed in the CISA KEV catalog, indicating no known active exploitation. No remote exploitation or privilege escalation is possible from this bug alone.
OpenCVE Enrichment
Debian DLA
Debian DSA