Impact
The vulnerability allows a remote attacker to obtain sensitive information by delivering a crafted HTML page that exploits the WebXR component in Google Chrome versions older than 152.0.7977.65. The exposure is an information disclosure; the CVE description does not state that the attack requires privileged user rights or additional system resources. Chromium rates the severity of the flaw as low.
Affected Systems
The affected product is the stable channel of Google Chrome on all supported operating systems. All releases prior to version 152.0.7977.65 contain the flaw. The vendor advises that any user running those versions is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity assessment and the EPSS score is below 1%, which suggests a low probability of exploitation. The CVE is not listed in the CISA KEV catalog. Exploitation requires a victim to visit a malicious web page that contains the crafted HTML; no other conditions or privileges are mentioned in the CVE data.
OpenCVE Enrichment
Debian DLA
Debian DSA