Impact
Information leak in Google Chrome's Core component prior to version 153.0.8010.36 allows a remote attacker to exfiltrate sensitive information from a victim’s system when the victim opens a specially crafted HTML page. The flaw exploits Core’s handling of sensitive data, exposing information such as cookies, form inputs, or cached files. This type of vulnerability is classified as a data‑exposure weakness (CWE‑200) and can compromise the confidentiality of user information, but it does not provide code execution or privilege escalation.
Affected Systems
Affected users run Google Chrome on any platform supported by the stable channel when the browser version is earlier than 153.0.8010.36. The issue does not affect later releases.
Risk and Exploitability
The CVSS score, 6.5, places this issue in the Medium severity range. The EPSS score is less than 1%, indicating a very low probability of exploitation, and it is not listed in the CISA KEV catalog. Chromium classifies the issue as Low severity. The attack vector requires a remote victim to load a malicious webpage; the flaw does not grant code execution but can expose confidential data, enabling credential theft or privacy violations. Although widespread exploitation is unlikely, the impact on confidentiality warrants timely patching.
OpenCVE Enrichment
Debian DLA
Debian DSA