Impact
An information leak exists in the Payments feature of Google Chrome versions before 152.0.7977.65. A crafted HTML page can trigger the browser to exfiltrate data that should be protected by the same‐origin policy, compromising confidentiality. This vulnerability aligns with CWE‑200, where improper isolation allows attackers to read sensitive information.
Affected Systems
Google Chrome for desktop, versions earlier than 152.0.7977.65.
Risk and Exploitability
The CVSS score for this vulnerability is 4.3, indicating low severity. The EPSS score is <1%, suggesting a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can supply a malicious HTML page that, if visited by a user with an active payment session in Chrome, may enable the attacker to read cross‑origin data that should be protected by the same‑origin policy. The attack requires the victim to open a crafted web page in Chrome and depend on the Payments feature.
OpenCVE Enrichment
Debian DLA
Debian DSA