Impact
An information leak (CWE-200) in the GPU component of Google Chrome before version 152.0.7977.65 lets a remote attacker extract cross‑origin data by delivering a specially crafted HTML page. The vulnerability enables the attacker to read data that should be confined to a different origin, compromising confidentiality. It is classified as high severity by Chromium.
Affected Systems
The flaw affects all Google Chrome installations older than 152.0.7977.65. Any device running the affected Chrome build is potentially vulnerable.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low but nonzero likelihood of exploitation. The CVSS score of 4.3 reflects a moderate impact. The attack vector is remote via a crafted HTML page, meaning an attacker can trigger the leak by driving a victim’s browser to a malicious site. Given the moderate confidentiality impact and lack of mitigation controls in the affected builds, the risk remains significant.
OpenCVE Enrichment
Debian DLA
Debian DSA