Impact
A flaw in Chrome’s FoldableAPIs allows a remote attacker to retrieve sensitive information by serving a specially crafted HTML page. The vulnerability exposes data that should be protected, satisfying the definition of information disclosure (CWE‑200). The CVSS score of 6.5 indicates low severity, indicating the payload does not automatically compromise the system but can leak useful data to an attacker.
Affected Systems
The issue exists in Google Chrome versions earlier than 152.0.7977.65. All releases on the stable channel before that build are vulnerable; newer builds contain the mitigation.
Risk and Exploitability
The vulnerability can be exploited remotely by enticing a user to open a malicious page, but no privileged code execution or escalation is required. Because the EPSS score is < 1% and the flaw is not listed in the CISA KEV catalog, the likelihood of widespread use is currently limited. Nonetheless, any user who visits untrusted sites faces a potential risk of data exposure.
OpenCVE Enrichment
Debian DLA
Debian DSA