Impact
The vulnerability arises from an observable discrepancy in the Autofill functionality of Google Chrome. When a malicious web page is rendered, the Autofill mechanism can leak sensitive data that the user has stored, such as passwords or credit card details. This results in a remote disclosure of confidential information, exposing credentials and payment data, and the weakness maps to CWE-203, an issue where unauthorized data exposure occurs.
Affected Systems
All users of Google Chrome on any platform running a version earlier than 153.0.8010.36 are affected. The flaw applies to desktop releases on Windows, macOS, Linux, and other operating systems that ship with the core Chrome engine at or below that version.
Risk and Exploitability
An attacker can trigger the flaw by serving a specially crafted HTML page to a victim's Chrome browser; no local code execution or elevated privileges are required. The attack vector is inferred from the description and is remote. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation likelihood is low. The CVSS score of 6.5 indicates medium severity, and the Chromium security severity is Medium, supporting the assessment that the vulnerability, while not highly severe, still warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA