Impact
GetUserMedia in Google Chrome versions prior to 152.0.7977.65 performs incomplete cleanup of media resources. If the renderer process is already compromised, an attacker can supply a malicious HTML page that tricks the renderer into leaking sensitive data, such as captured audio or video, through the still‑alive media stream. The vulnerability is classified as a medium severity event by Chromium, reflecting the potential for confidential information exposure once the attack conditions are met.
Affected Systems
Affected products include the stable channel of Google Chrome on desktop platforms before the 152.0.7977.65 update. Any device running those versions – whether Windows, macOS, or Linux – is susceptible to this flaw. The issue was fixed in the 152.0.7977.65 release, so applied updates eliminate the risk.
Risk and Exploitability
Risk and exploitability are constrained by the need for the attacker to have already subverted the renderer process and to persuade the user to load a crafted page that triggers the residual media stream. The CVSS score of 5.3 indicates medium severity, and the EPSS score of < 1% indicates a low probability of exploitation, while its absence from the CISA KEV catalog suggests no large‑scale exploitation is currently documented. Nonetheless, the CWE‑459 weakness alerts to a non‑trivial likelihood of data leakage if the attack prerequisites are satisfied. Users running unpatched browsers should consider the possibility of social‑engineering attacks that prompt media access.
OpenCVE Enrichment
Debian DLA
Debian DSA