Impact
The flaw allows a remote attacker to read unprotected data during browsing of a specially crafted HTML page. The vulnerability is categorized as a medium‑severity information disclosure issue that can expose sensitive information to the attacker. No additional user privileges or system components are required beyond the normal rendering of the page.
Affected Systems
Google Chrome on Windows versions prior to 153.0.8010.36 are affected. The issue applies to the Enterprise distribution of the browser and affects all users on systems running these releases.
Risk and Exploitability
The vulnerability can be exploited remotely by serving the crafted page to a user, typically through a malicious website or an in‑mail link. Because the flaw is limited to the rendering engine of the browser, it does not provide remote code execution or privilege escalation, but the information gained could be leveraged in later attacks. The CVSS score is 6.5, which is Medium, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog, so public exploitation is not confirmed yet, yet the risk is non‑negligible if the software remains unpatched.
OpenCVE Enrichment
Debian DLA
Debian DSA