Impact
The vulnerability is a side-channel information leakage in WebCodecs, allowing a remote attacker to read potentially sensitive data from process memory through a crafted HTML page. The incident can expose confidential user data without requiring authentication or code execution, representing a data disclosure flaw.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 are affected; the issue is present in the Chrome browser shipped by Google.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector involves a malicious web page in the user’s browser; a remote attacker must convince a user to visit the crafted page, after which the side‑channel leak can be triggered.
OpenCVE Enrichment
Debian DLA
Debian DSA