Impact
The vulnerability lies in the handling of animation data in Google Chrome prior to version 155.0.8059.39. A crafted HTML page can trigger an information leak that exposes sensitive data to a remote attacker. This flaw is categorized as information exposure, allowing the attacker to read data beyond intended boundaries, which could include user credentials or local content. The impact is disclosure of private information rather than code execution or denial of service.
Affected Systems
The affected product is Google Chrome before version 155.0.8059.39. Users running any older Chrome release are potentially vulnerable. The issue was fixed in Chrome 155.0.8059.39, the latest stable release at the time of the patch.
Risk and Exploitability
The CVSS score is not provided in the CVE data, and an EPSS score is not available, indicating no precise exploit probability estimate. Chrome describes the flaw as medium severity, and it is not present in the CISA KEV catalog, so no publicly documented exploits are known. The likely attack vector is a remote web page that a user visits or a local file that contains crafted HTML; user interaction is required to load the page so that the animation flaw can be leveraged to read data outside the normal scope.
OpenCVE Enrichment