Impact
The vulnerability is an incomplete cleanup in the Proxy Auth handling code in Google Chrome. An attacker adjacent to the affected system could craft network traffic that triggers the flaw and causes the browser to expose sensitive data that should have been discarded. The high severity rating indicates that this information disclosure could expose credentials or other confidential data exchanged between the user and a proxy server.
Affected Systems
Google Chrome versions prior to 155.0.8059.39 are affected. This includes the stable channel releases up to that build.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog, but the medium severity rating still highlights the potential for information disclosure. The flaw requires an attacker to be able to send crafted Proxy-Authorization packets on the network segment where the target Chrome instance resides. Because the attacker must be adjacent, the threat surfaces mainly in shared or untrusted network environments. Once the condition is met, the browser leaks data that should have been purged.
OpenCVE Enrichment