Impact
An input validation flaw in Google Chrome’s Sync component allows a remote attacker to supply specially crafted network traffic, which can lead to the disclosure of sensitive information. The flaw exists in Chrome versions prior to 152.0.7977.65 and is classified as a medium‑severity issue by Chromium developers.
Affected Systems
Based on the description, it is inferred that all desktop users running Google Chrome releases before 152.0.7977.65 with Sync enabled are affected. The issue pertains to the Sync component handling cloud‑stored data synchronization.
Risk and Exploitability
The vulnerability permits a remote attacker to send specially crafted network traffic to Chrome’s Sync component, potentially exposing sensitive data. The description does not specify whether authentication is required, so it is unclear if the attacker needs valid Chrome credentials or can target any user with Sync enabled. The CVSS score of 6.5 reflects a medium severity, the EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Overall, the risk is moderate and primarily threatens the confidentiality of information stored in Sync.
OpenCVE Enrichment
Debian DLA
Debian DSA