Impact
The vulnerability is a data leakage in the Network component of Google Chrome prior to version 152.0.7977.65. When a remote attacker has already compromised the renderer process, a specially crafted HTML page can cause the browser to expose sensitive information. This undermines confidentiality by allowing unauthorized access to data held within the renderer. The weakness is identified as CWE‑200.
Affected Systems
Google Chrome browsers running any version older than 152.0.7977.65 are affected. No specific operating systems are mentioned, so the issue applies to all platforms where the stated Chrome versions are installed.
Risk and Exploitability
Chromium labels the issue as medium severity with a CVSS score of 5.3 and an EPSS score of less than 1%. The exploit requires the attacker to have already compromised the renderer process, indicating that a prior vulnerability or local privilege would be needed. Because a specially crafted HTML page is necessary, the most likely attack vector is a remote web-page exploit that gains renderer control. The risk level remains moderate, and the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment
Debian DLA
Debian DSA