Impact
The vulnerability is an information leak in the proxy component of Google Chrome on Windows. An attacker who can observe or influence the network traffic adjacent to the system can craft specific packets that cause Chrome to expose sensitive information. The weakness is a classic information disclosure flaw (CWE-200) and is rated high severity by Chromium security team. The impact is limited to the data that Chrome reveals through the proxy path; it does not provide direct code execution or privilege escalation.
Affected Systems
Google Chrome on Windows versions earlier than 155.0.8059.39 are affected. Users running the Stable channel of Chrome on Windows should check their version and upgrade if they are on an earlier build.
Risk and Exploitability
No publicly available EPSS score is reported, but the CVSS score of5.3 indicates a medium severity level for this information disclosure vulnerability. The vulnerability is not listed in CISA’s KEV catalog, indicating no known exploited instances. Attackers would still need local or network proximity to send crafted traffic to the proxy used by Chrome; no remote arbitrary code execution is possible from the information presented.
OpenCVE Enrichment