Impact
Information leak in Google Chrome's Core component prior to version 153.0.8010.36 allows a remote attacker to exfiltrate sensitive information from a victim’s system when the victim opens a specially crafted HTML page. The flaw exploits Core’s handling of sensitive data, exposing information such as cookies, form inputs, or cached files. This type of vulnerability is classified as a data‑exposure weakness (CWE‑200) and can compromise the confidentiality of user information, but it does not provide code execution or privilege escalation.
Affected Systems
Affected users run Google Chrome on any platform supported by the stable channel when the browser version is earlier than 153.0.8010.36. The issue does not affect later releases.
Risk and Exploitability
EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Chromium classifies the issue as Low severity, indicating limited exploitation potential. The attack vector requires a remote victim to load a malicious webpage; the flaw does not grant code execution, but it can expose confidential data, making credential theft or privacy violations possible. While widespread exploitation is unlikely, the risk is considered moderate and should be mitigated promptly.
OpenCVE Enrichment