Impact
A vulnerability in the Animation component of Google Chrome allowed a remote attacker to leak application data by loading a specially crafted HTML page. The weakness is a classic information‑leak flaw (CWE‑200) and enables the attacker to read data that should remain private to the browser process.
Affected Systems
Google Chrome is affected. Versions prior to 152.0.7977.65 are vulnerable, while all later releases contain the fix. The issue does not affect non‑Chrome browsers or other Google products.
Risk and Exploitability
The vulnerability can be triggered by visiting a malicious web page, so the likely attack vector is remote and web‑based as inferred from the description. No publicly available exploits are reported, and the CVE is not listed in the CISA KEV catalog. The CVSS score of 6.5 places it in the medium severity range, and with an EPSS score of less than 1%, the likelihood of exploitation remains low, but the potential for sensitive data exposure warrants patching.
OpenCVE Enrichment
Debian DLA
Debian DSA