Impact
The vulnerability enables an attacker to leak sensitive data by serving a specially crafted HTML page that triggers a QUIC protocol handling flaw in Google Chrome versions prior to 152.0.7977.65. The defect results in unintended disclosure of private information without requiring local code execution or elevated privileges, thereby compromising confidentiality of the user.
Affected Systems
Chrome installers below version 152.0.7977.65 are affected. Users on the stable channel who have not installed the August 2026 update remain at risk. All platforms that ship this version of Chrome are potentially exposed until patched.
Risk and Exploitability
The CVSS score of 6.5 classifies this as medium severity by Chromium. The EPSS score indicates a very low probability of exploitation. The vulnerability is not in CISA’s KEV catalog. Exploitation requires only a network-based attack from a malicious web page; no local privileges are needed, making the attack vector straightforward for an attacker with a compromised site.
OpenCVE Enrichment
Debian DLA
Debian DSA