Impact
A crafted HTML page can trigger an information leak in the Transactions Platform of Google Chrome versions before 153.0.8010.36. The flaw allows a remote attacker to read sensitive data that should not be exposed to web content, resulting in a confidentiality compromise per CWE‑200.
Affected Systems
The vulnerability impacts all Chrome installations using versions older than 153.0.8010.36, regardless of operating system or device type.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating low severity, and an EPSS score of less than 1%, and it is not listed in the CISA KEV catalog. The likely attack vector is a remote exploit where an adversary hosts a malicious web page; the attacker would need only a victim who opens the page in a vulnerable Chrome instance. Due to its low severity and lack of published exploitation, the immediate risk is moderate, but the potential for data leakage remains real if a user visits a malicious site.
OpenCVE Enrichment
Debian DLA
Debian DSA