Impact
The vulnerability is a DOM-based information leak in Google Chrome versions prior to 152.0.7977.65. A remote attacker can trigger the leak by delivering a crafted HTML page to a user. When the victim loads the page, the browser may release sensitive data from the DOM to the attacker. This flaw is classified as CWE-200, indicating that confidential information can be disclosed to an unauthorized party.
Affected Systems
Affected systems are Google Chrome browsers on all platforms that have not yet upgraded past version 152.0.7977.65. Users running the stable channel after the August 2026 update are not impacted.
Risk and Exploitability
The CVSS score is 6.5, and the EPSS score is < 1%. Chromium has rated the flaw as medium severity. It is not listed in the CISA KEV catalog. Exploitation requires the victim to open a specifically crafted HTML page, so the attack vector is social engineering, limiting the attack window to users deceived into loading the malicious content.
OpenCVE Enrichment
Debian DLA
Debian DSA