Impact
Improper input validation in the Sync component of Google Chrome prior to 152.0.7977.65 allows a remote attacker to craft network traffic that may expose sensitive information. The weakness can lead to unauthorized disclosure of data, compromising confidentiality. The flaw is rooted in CWE-20, reflecting inadequate handling of external input.
Affected Systems
Google Chrome browsers released before version 152.0.7977.65 are affected. Users of the stable channel who have not yet updated to 152.0.7977.65 or newer versions remain vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9, indicating medium severity, yet the EPSS score is 0.00341, indicating a very low exploitation probability. It is not present in the CISA KEV catalog. Attackers would need to send crafted network packets to a victim’s Chrome session utilizing Sync, and the flaw does not require elevated privileges. The risk is primarily for users whose Chrome client is out of date.
OpenCVE Enrichment
Debian DLA
Debian DSA