Impact
An inconsistency in how Google Chrome processes form data before version 152.0.7977.65 can be triggered by a webpage crafted by a remote attacker. The flawed handling allows the browser to expose data that the user intended to keep private, such as form field contents, without the user's consent. This results in an information‑disclosure weakness (CWE-203).
Affected Systems
Google Chrome browsers running any release older than 152.0.7977.65 are susceptible to this vulnerability. The CVE data does not specify limits to a specific channel or platform.
Risk and Exploitability
Chromium indicates a CVSS score of 5.3 for this defect, and the vulnerability can be exploited from a remote web page that a user visits. The EPSS score is < 1%, indicating a very low exploitation probability, and the absence of a KEV listing suggests that mass exploitation has not been observed publicly. Nonetheless, the attack is straightforward for an adversary who can host a malicious page, making it a realistic threat to users who visit untrusted sites.
OpenCVE Enrichment
Debian DLA
Debian DSA