Impact
The vulnerability occurs in the MediaCapture component of Google Chrome. A crafted HTML page can trigger the component to expose sensitive information to a remote attacker. This is an information‑disclosure flaw classified as CWE‑200, allowing data leakage without requiring authentication or privileged access.
Affected Systems
Affected systems include any Google Chrome installation prior to version 152.0.7977.75. Users with older Chrome versions on the stable channel are at risk. The issue is reported for the desktop stable channel and has been addressed in releases after 152.0.7977.75.
Risk and Exploitability
The risk is medium as per Chromium's internal severity. Exploitation requires a user to visit or open a malicious web page that contains a crafted MediaCapture request. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. As a remote, client‑side vulnerability, patching by upgrading Chrome is the definitive mitigation.
OpenCVE Enrichment