Impact
The vulnerability exists in Chrome's DataTransfer component, allowing a crafted HTML page to read sensitive information that should be protected. An attacker who can host or influence a page visited by a user could capture data that the browser should keep private, impacting confidentiality of that data. The weakness corresponds to information disclosure (CWE-200).
Affected Systems
Google Chrome browsers on desktop platforms with versions earlier than 152.0.7977.65 are affected. This includes all Chrome stable releases prior to the 152.0.7977.65 update.
Risk and Exploitability
The CVSS score of 6.5 reflects a medium severity, and the EPSS score is less than 1%, indicating a low likelihood of exploitation. The vulnerability is triggered by a maliciously crafted web page, giving an attacker a remote vector via the user's browser. No public exploits are known, and it is not listed in CISA's KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA