Impact
Observable differences in Chrome’s Network component before version 152.0.7977.65 allow a remote attacker to obtain sensitive data through a crafted HTML page. The flaw is classified as a medium‑severity information‑disclosure weakness, labeled CWE‑203, indicating that improper data handling can expose confidential material. The CVSS score of 5.3 confirms a medium severity level.
Affected Systems
Google Chrome Desktop versions earlier than 152.0.7977.65 are affected. The issue is observed in the desktop channel; based on the description, it is inferred that mobile or other variants are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, and the EPSS score is < 1%, indicating low exploitation probability; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, requiring an attacker to host a maliciously crafted HTML page that a victim must load in the vulnerable browser. Once loaded, the network discrepancy can expose sensitive data. No active exploitation has been reported, so the risk is considered moderate until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA