Impact
An information leak was discovered in the Downloads module of Google Chrome versions prior to 153.0.8010.36. When the renderer process was compromised, a maliciously crafted HTML page allowed the attacker to read data from other origins, exposing sensitive information across origin boundaries. The defect is classified as a medium severity issue by Chromium, aligning with its CVE description.
Affected Systems
Affected installations are any Chrome versions older than 153.0.8010.36 on any operating system that runs the renderer process for handling user‑initiated downloads and page rendering. All platforms where the browser operates in a typical desktop configuration fall under this scope.
Risk and Exploitability
The CVSS base score of 3.1 and an EPSS value below 1% indicate a low likelihood of widespread exploitation. Because the vulnerability requires an already compromised renderer process, it is generally limited to environments where an attacker can gain such foothold. The issue is not listed in the CISA KEV catalog. Prompt patching remains the most effective mitigation against this potential cross‑origin data leakage.
OpenCVE Enrichment
Debian DLA
Debian DSA