Impact
A crafted HTML page can trigger a flaw in Navigation handling within Google Chrome that allows a remote attacker to read data from another origin. The vulnerability is a case of information disclosure (CWE‑203) and could lead to the exposure of sensitive site information to an attacker controlling a malicious web page. This issue is not a code execution or denial‑of‑service flaw; its outcome is the unintended release of cross‑origin content rather than system compromise.
Affected Systems
The flaw exists in Google Chrome on the stable channel for any installation before version 153.0.8010.36. Users running earlier stable builds are vulnerable until the update that corrects the navigation discrepancy is installed. No other vendors or product variants are listed in the advisory.
Risk and Exploitability
An EPSS score of 0.00241 indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, so publicly known exploitation data is limited. The CVSS score of 4.3 confirms a medium‑severity rating, and the EPSS score of 0.00241 indicates a very low exploitation probability, so the actual risk to an organization depends on the likelihood that an attacker can serve a malicious page to the target user. Because the flaw requires a crafted page in the victim’s browser, the threat vector is typically remote via the web.
OpenCVE Enrichment
Debian DLA
Debian DSA