Impact
Improper state validation in the Performance component of Google Chrome allowed a remote attacker to read memory inside the sandbox environment through a crafted HTML page. This flaw can expose confidential data to an attacker and represents a high‑severity issue. The weakness is classified as CWE-754, improper use of a system resource or state.
Affected Systems
Google Chrome browser is affected. Versions of Chrome prior to 152.0.7977.65 are vulnerable. The issue arises specifically in the Performance module of the Chrome rendering engine.
Risk and Exploitability
The vulnerability is exploitable from a remote context by delivering a specially crafted HTML page to the victim’s browser, enabling memory disclosure within the sandbox. The CVSS score of 8.1 indicates high severity, and the EPSS score is below 1%, suggesting a low probability of exploitation. The flaw does not appear in the CISA KEV catalog, implying that publicly known, active exploits are not yet identified, but the potential impact warrants immediate attention.
OpenCVE Enrichment
Debian DLA
Debian DSA