Impact
A flaw in the implementation of the HTML SELECT event in Google Chrome before version 153.0.8010.36 lets a remote attacker craft a web page that reveals sensitive data. The vulnerability is an example of informational exposure (CWE‑203) and permits unintended leakage of data that may be present in the user’s browser context. The attacker cannot execute code or modify system state; the primary consequence is that confidential information may be read by a malicious site.
Affected Systems
All Google Chrome users running a pre‑153.0.8010.36 build are affected. The flaw is tied specifically to the specified Chrome version and is not present in later releases.
Risk and Exploitability
The flaw is classified as Chromium security severity Low. The CVSS score is 6.5, indicating a medium severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the issue is not listed in the CISA KEV catalog, suggesting a low public exploit likelihood. The attack vector inferred from the description is remote via a crafted HTML page, meaning the user must visit or load a malicious page in a Chrome session. Given the medium severity and the fact that the issue is merely a data read, exploitation is unlikely to have immediate widespread consequence.
OpenCVE Enrichment
Debian DLA
Debian DSA