Impact
The vulnerability allows a remote attacker who has compromised Chrome’s renderer process to read sensitive data via a specially crafted HTML page, representing a medium‑severity confidentiality risk.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. The issue involves the renderer component and is mitigated by upgrading to the fixed release.
Risk and Exploitability
With a CVSS score of 5.3 and an EPSS score of less than 1%, exploitation is considered low prevalence. The flaw requires the attacker to first compromise the renderer process; once that foothold is achieved, the attacker can retrieve data visible in that rendering context. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA