Impact
The vulnerability is an information‑leak flaw in the way Google Chrome processes CSS. A crafted HTML page can trigger the leak, allowing a remote attacker to gather sensitive data that the page had access to. The flaw falls under CWE‑200, meaning it is a data‑exposure weakness. Although the Chromium security team rated it Medium, the attack could expose personal or business information from the victim’s browser session.
Affected Systems
Only Google Chrome is affected, specifically any build prior to Chrome version 152.0.7977.65. The vendor list confirms that the flaw exists in the Chrome product line, and no further version work‑arounds or patches are listed in the input. The affected version range is therefore incomplete, but the recommendation is to update to 152.0.7977.65 or later.
Risk and Exploitability
The risk is moderate; the CVSS score is 6.5, the EPSS score is < 1%, and the vulnerability is not present in the CISA KEV catalog. Attackers would need to host a malicious HTML page that they could serve to a target. Because the information leak occurs via CSS parsing and does not require elevated privileges or local code execution, the primary attack vector is remote and requires network access to the victim’s browser. Exploit development is simple, but success depends on the victim visiting the crafted page.
OpenCVE Enrichment
Debian DLA
Debian DSA