Impact
An observable discrepancy in Google Chrome's Performance APIs allows a remote attacker to read cross‑origin data from a crafted webpage. The flaw is identified as CWE‑203, meaning internal data is unintentionally revealed. The attacker could obtain sensitive metrics such as timestamps or navigation timings that belong to other origins, potentially exposing timing information that can aid further attacks.
Affected Systems
The vulnerability potentially affects any Google Chrome version that implements the affected Performance API before the fix is released. According to the description, all Chrome releases prior to version 152.0.7977.65 are vulnerable. Users should assume all older or unpatched Chrome installations are at risk until an official update resolves the discrepancy.
Risk and Exploitability
The issue can be triggered by uploading or visiting a malicious web page that the victim loads in Chrome, making the attack vector user‑directed and remote. The CVSS score of 6.5 indicates medium severity, and the EPSS score of < 1% suggests a low likelihood of exploitation in the near term. Although not listed in the CISA KEV catalog, the potential for cross‑origin data leakage warrants prompt action.
OpenCVE Enrichment
Debian DLA
Debian DSA