Impact
This vulnerability arises from a CORS misconfiguration in Google Chrome that allows an attacker who has already compromised the renderer process to retrieve cross‑origin data through a specially crafted HTML page. The result is that confidential information from other origins can be exposed without any additional privileges, representing a clear information‑disclosure flaw (CWE‑200).
Affected Systems
Google Chrome browsers on any platform running a version earlier than 153.0.8010.36 are affected. Users should verify that their local installation is not within this range.
Risk and Exploitability
The CVE is rated medium severity and is not listed in CISA's KEV catalog, indicating there is no documented exploitation yet. The EPSS score of 0.00174 indicates a very low but non‑zero exploitation probability. The attack requires the attacker to have already gained control of the renderer process, typically through another vulnerability or malicious web content, and then serve a page that triggers the CORS leak. Due to this prerequisite, the exploitation window is narrower than for purely remote code execution bugs, but the potential for data exposure remains significant if the conditions are met.
OpenCVE Enrichment
Debian DLA
Debian DSA