Impact
The vulnerability resides in the Views component of Google Chrome on macOS. A local attacker can create a specially crafted HTML page that, when viewed in Chrome, triggers an inappropriate memory read. This allows the attacker to read data stored in the browser process’s memory, potentially exposing sensitive information such as personal data and credentials. The weakness matches CWE‑200, Information Exposure.
Affected Systems
Google Chrome for macOS versions released prior to 151.0.7922.72. The reference to the stable‑channel update confirms that the issue applies to the stable channel on macOS.
Risk and Exploitability
The CVSS score of 6.2 places the vulnerability in the medium severity range, while the EPSS score of less than 1 % indicates a low probability of exploitation in the wild. It is not listed in CISA’s KEV catalog. The likely attack vector is local – the attacker must be able to open a crafted HTML page in the victim’s Chrome session. No elevated privileges or remote access are required, but the attacker can read confidential data from memory during normal browsing.
OpenCVE Enrichment
Debian DLA
Debian DSA