Impact
A confused deputy flaw in the CredentialProvider in Google Chrome on Windows before 152.0.7977.75 lets a remote attacker who has already compromised the renderer process leak sensitive information through a specially crafted HTML page, resulting in a disclosure of credentials or other protected data. The weakness is categorized as CWE‑441 and is considered a low severity issue by Chromium security.
Affected Systems
The vulnerability affects Google Chrome running on Windows systems, specifically versions earlier than 152.0.7977.75. An attacker must target a system where Chrome’s renderer process is running the untrusted content.
Risk and Exploitability
The EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. The CVSS severity is low, and successful exploitation requires the attacker to have already positioned themselves within the renderer process via malicious web content. This makes the attack vector constrained and dependent on a pre‑existing compromise of the browser’s rendering engine.
OpenCVE Enrichment