Impact
The vulnerability occurs in Google Chrome’s MediaCapture component prior to version 152.0.7977.75. A crafted HTML page can trigger the component to expose sensitive information, resulting in an information‑disclosure flaw classified as CWE‑200. The flaw allows a remote attacker to potentially read data from the user’s media devices without authentication or privileged access.
Affected Systems
Affected systems include any Google Chrome installation earlier than 152.0.7977.75 on the stable channel. Users of older Chrome versions, whether on Windows, macOS, or Linux, are susceptible. The issue has been addressed in releases newer than 152.0.7977.75 and is listed in Google’s stable channel update log.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. Exploitation requires a user to load a malicious web page that contains a crafted MediaCapture request. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. As a client‑side remote vulnerability, the primary mitigation is to upgrade Chrome to a patched version and to rely on automatic update mechanisms to receive timely security fixes.
OpenCVE Enrichment
Debian DLA
Debian DSA