Impact
An adversary adjacent to the target machine can craft network traffic that exploits a flaw in the Proxy component of Google Chrome on Windows. The flaw allows the attacker to read or obtain sensitive information that is otherwise protected, potentially leaking confidential data. This vulnerability is characterized as an instance of improper so‑called "incorrect provision" of functionality, indicating the software fails to safeguard data when communicating over proxy channels.
Affected Systems
Windows users running Google Chrome version 152.0.7977.64 or earlier are affected; upgrading to 152.0.7977.65 or later eliminates the issue.
Risk and Exploitability
The vulnerability is considered low severity by Chromium, with a CVSS score of 5.9. The EPSS score is reported as less than 1%, indicating a low likelihood of exploitation. It is not listed in the CISA KEV catalog, and no public exploit has been reported. The attack vector is likely local or relay-based—an attacker adjacent to the victim could manipulate packets without needing remote access. Because the flaw stems from a CWE‑684 weakness, successful exploitation would depend on crafted traffic being processed by the vulnerable client.
OpenCVE Enrichment
Debian DLA
Debian DSA