Impact
The vulnerability allows a remote attacker to induce Chrome to render a page layout in a way that leaks sensitive information from the page. By serving a crafted HTML page, an attacker can cause the browser to expose data without requiring authentication or local execution. This weakness is classified as CWE-203 and CWE-204, where unauthorized access to a permitted resource occurs.
Affected Systems
The affected software is Google Chrome. All versions released prior to 153.0.8010.36 are vulnerable. The vendor’s release notes indicate that the issue is fixed in the stable channel update that contains 153.0.8010.36.
Risk and Exploitability
The CVSS score for this issue is 5.3, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. An attacker must host or deliver a malicious web page that exploits the layout discrepancy to extract data. While the current exploitation probability appears low, the medium severity and the fact that the flaw can be triggered by simply loading a page mean that the risk to environments that rely on Chrome for sensitive browsing is noteworthy. The primary attack vector is likely phishing or other malicious websites that can serve crafted HTML.
OpenCVE Enrichment
Debian DLA
Debian DSA