Impact
Improper input validation in the Network component of Google Chrome on Windows allows a remote attacker who tricks a user into opening a specially crafted HTML page to read sensitive data. The flaw arises because the browser processes data from an untrusted source without sufficient sanitization. This vulnerability is classified as a low‑severity information disclosure and is identified as CWE-20.
Affected Systems
The vulnerability affects users of Google Chrome versions earlier than 152.0.7977.65 running on Windows. Systems with later releases or other operating systems are not impacted.
Risk and Exploitability
The attack requires user interaction, typically delivered through a phishing or social‑engineering campaign. No public exploits are reported and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is < 1%, indicating a very low probability of exploitation. The CVSS score of 6.5 signifies moderate severity of the information disclosure. Installing the patched Chrome release eliminates the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA