Impact
An improper input validation bug is present in Google Chrome’s password handling subsystem, enabling a remote attacker to potentially leak sensitive information through crafted network traffic. The flaw may lead to the disclosure of user credentials or other confidential data, resulting in a confidentiality compromise. It corresponds to the widely recognized weakness of improper input validation (CWE‑20).
Affected Systems
The vulnerability affects Google Chrome versions earlier than 153.0.8010.36 on all supported platforms. Versions 153.0.8010.36 and later include the fix for this input‑validation issue.
Risk and Exploitability
The attack vector is remote, relying on malicious or compromised network traffic that Chrome will receive, for example via a malicious website or network intrusion. The CVSS score is 5.9, indicating a medium severity level. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no documented large‑scale exploitation yet. Nonetheless, any user of a vulnerable Chrome release faces a non‑trivial risk of data leakage until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA