Impact
Inappropriately implemented view handling in Google Chrome for macOS enabled a local adversary to read sensitive data from process memory. By loading a specially crafted HTML page, an attacker can trigger the flaw and obtain confidential information. The weakness falls under CWE-200, an information exposure flaw, and the impact is limited to confidentiality loss for the user’s data within the local environment.
Affected Systems
The vulnerable product is Google Chrome on macOS, versions older than 151.0.7922.72. Any Chrome build prior to 151.0.7922.72 on macOS is susceptible.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires a local attacker who can open or inject the crafted HTML page within Chrome, so the attack vector is local and confined to the user's machine.
OpenCVE Enrichment
Debian DLA
Debian DSA