Impact
An information‑leak vulnerability exists in the SignIn process of Google Chrome versions older than 152.0.7977.65. When a remote attacker sends specially crafted network traffic to a victim’s browser, the browser may inadvertently expose sensitive information that should remain confidential, a flaw classified as CWE‑200. The breach compromises data confidentiality but does not provide privileges or modification rights.
Affected Systems
The CVE affects all releases of Google Chrome prior to version 152.0.7977.65 on every platform; the affected builds are independent of operating system or release channel. The vulnerability was addressed in the August 2026 stable channel update announced by Google. Vendors other than Google are not listed as impacted.
Risk and Exploitability
The vulnerability carries a medium severity with a CVSS score of 5.9. The EPSS score of < 1 % indicates a very low probability of public exploitation, and the issue is not listed in the CISA KEV catalog. The attack vector is remote, requiring the attacker to control the network traffic that reaches the victim’s browser. No public exploits have been observed, so while the confidentiality impact is concrete, the overall risk remains moderate under current threat conditions.
OpenCVE Enrichment
Debian DLA
Debian DSA