Impact
The vulnerability originates in Chrome's Bluetooth implementation on macOS versions earlier than 152.0.7977.65. If an adversary has compromised the renderer process, they can craft an HTML page that, through social engineering, gathers sensitive data from the compromised process and exposes it to the attacker. The result is the leakage of confidential information rather than a denial of service or code execution. This weakness is catalogued as CWE-200, indicating improper handling of confidential information.
Affected Systems
Google Chrome users running macOS with versions before 152.0.7977.65 are affected. The issue is specific to the desktop Chrome stable channel on macOS. All other versions and platforms are not impacted.
Risk and Exploitability
The Chromium security team assessed the issue with a CVSS score of 5.3, indicating a Medium severity. The EPSS score of < 1% and the absence from the CISA KEV catalog suggest a low probability of exploitation. An attacker must first compromise the renderer process and then employ social engineering to trick a user into visiting a maliciously crafted page. Because the vulnerability requires such preconditions, the overall risk remains modest, but the potential exposure of sensitive information warrants immediate action.
OpenCVE Enrichment
Debian DLA
Debian DSA