Impact
This vulnerability allows a remote attacker who has already compromised the renderer process to read cross‑origin data using a specially crafted HTML page. The flaw results in an information leak without requiring local user interaction, exposing sensitive data that the renderer is permitted to access. The weakness is an implicit information disclosure, classified as CWE‑200.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are affected. The flaw resides in the renderer component of the Chrome browser distributed by Google.
Risk and Exploitability
Based on the description, it is inferred that the attack vector requires the attacker to first gain control of the renderer process, which typically indicates a broader compromise of the browser or the underlying system. No public exploitation data are available and the vulnerability is not listed in CISA's KEV catalog. The CVSS score of 4.3 and the EPSS score of < 1% suggest a moderate severity; when the prerequisite conditions are met, the flaw can lead to significant data exposure. The lack of a list in the KEV catalog and the low EPSS score mean that, although the vulnerability exists, the likelihood of widespread exploitation is low.
OpenCVE Enrichment
Debian DLA
Debian DSA