Impact
ControlledFrame is a component of Chrome that handles frame boundaries. The vulnerability enables a remote attacker who has already compromised the renderer process to read sensitive information from memory by loading a specially crafted HTML page. Classified as CWE‑200, the flaw can result in accidental disclosure of private data residing in the renderer’s memory space.
Affected Systems
All installations of Google Chrome with versions earlier than 153.0.8010.36 are vulnerable. The security fix is included in Chrome version 153.0.8010.36 and later.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score of < 1% shows a very low probability that the vulnerability is actively exploited, and it is not listed in the CISA KEV catalog. Exploitation requires a prior compromise of the renderer process, which represents a non‑trivial barrier. Consequently, the likelihood of exploitation by general adversaries is limited, but it remains a concern for attackers capable of achieving renderer‑level compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA