Impact
Information leak in the WebMCP component of Google Chrome prior to version 153.0.8010.36 allows a remote attacker who has already compromised the renderer process to retrieve cross‑origin data by serving a specially crafted HTML page. The flaw is a classic information‑disclosure vulnerability that can expose sensitive content to a malicious script running in a different origin. The impact is limited to victims whose renderer process has been compromised, but once compromised it permits pervasive data extraction across origins.
Affected Systems
All installations of Google Chrome with a stable channel version earlier than 153.0.8010.36 are affected. This includes Windows, macOS, Linux and other platforms that ship the stable channel of Chrome without the WebMCP patch. Newer revisions of Chrome, starting with 153.0.8010.36 and beyond, contain the fix and are not vulnerable.
Risk and Exploitability
The EPSS score is 0.00241, indicating an extremely low likelihood, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate baseline risk. However, the attack requires that an adversary can execute code inside the renderer process, which typically requires exploitation of another vulnerability or social‑engineering techniques. The CVSS score is 3.1, indicating a low level of severity, but the Chromium severity is Medium. Overall, the risk is contingent on the ability to compromise the renderer; if that is achieved, the attacker can exfiltrate cross‑origin data with a moderate to high potential impact.
OpenCVE Enrichment
Debian DLA
Debian DSA