Impact
A discrepancy in the way Google Chrome renders HTML in versions before 152.0.7977.65 allows a remote attacker to craft a malicious page that, when viewed, produces an observable difference in the browser’s output. This difference can be used to infer or directly read sensitive information that the user holds while browsing. The weakness is characterized as an information exposure flaw (CWE-203).
Affected Systems
The vulnerability affects Google Chrome on all platforms for any stable channel release whose version is earlier than 152.0.7977.65. Users who have not upgraded to at least this version are potentially exposed. No other products or vendor versions are listed as affected.
Risk and Exploitability
Chromium classifies the issue as medium severity with a CVSS score of 5.3, and the EPSS score is < 1%, indicating no publicly confirmed exploit. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited exploitation. Nevertheless, because the flaw permits remote data leakage through a crafted web page, the risk is non‑trivial; any user who visits an attacker‑controlled site could have private data exposed. Patch availability makes the situation manageable, but users on older versions remain at risk.
OpenCVE Enrichment
Debian DLA
Debian DSA