Impact
A flaw in the Glic handling code of Google Chrome, observable in versions prior to 152.0.7977.65, allows a remote attacker to cause a browser to expose sensitive information. The bug can be triggered from a crafted HTML page served over the network, and the Chromium team rated the internal security severity of the issue as low. The impact is strictly an information disclosure; it does not give the attacker code execution, privilege escalation, or denial of service capabilities.
Affected Systems
Google Chrome running on desktop platforms is affected, specifically any installation that has not reached version 152.0.7977.65 or newer. The issue is confined to the browser’s rendering engine and does not affect other Google services or operating system components.
Risk and Exploitability
The CVSS score for this vulnerability is 5.3, and its EPSS score is less than 1%; the vulnerability is not listed in the CISA KEV catalog. The attack requires the user to open a specially crafted web page, so it is a client‑side exploit that can be performed remotely. The Chromium stability score notes low severity, indicating that while the information leak is real, the overall risk to enterprise users is moderate and not likely to be widely exploited in the wild at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA