Impact
An off‑by‑one error in Chrome’s Developer Tools allows a remote attacker, who can trick a user into installing a tailored extension, to read memory inside the browser’s sandbox. This can expose confidential data such as credentials or code, though it does not provide code execution or direct control over the system.
Affected Systems
The issue affects Google Chrome versions prior to 152.0.7977.65 on desktop platforms. Users running earlier builds are at risk until they upgrade to the fixed release or later.
Risk and Exploitability
EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating no evidence of active exploitation. The CVSS score of 9.1 indicates high severity, but the likelihood of successful exploitation remains low due to the need for a malicious extension delivered via social engineering. Updating mitigates the risk completely.
OpenCVE Enrichment
Debian DLA
Debian DSA