Impact
The vulnerability is an observable discrepancy in the Prefetch behaviour of Google Chrome that permits a remote attacker to leak cross‑origin information through a specially crafted HTML page. This flaw is classified as a confidentiality issue and is identified as CWE‑203 and CWE‑204, highlighting that the browser can expose data that should be protected from cross‑origin readers.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 are affected by this Prefetch data‑leak issue.
Risk and Exploitability
The flaw receives a low severity rating of 4.3 and no EPSS score is available, and it is not listed in the CISA KEV catalog. The likely attack vector is remote, with an attacker delivering a crafted web page that a victim opens in Chrome; the Prefetch mechanism then exposes data from a different origin. Because the attack requires simply a victim’s browser to load the malicious page, the risk is considered low, but any scenario that involves sensitive cross‑origin information could be impacted.
OpenCVE Enrichment
Debian DLA
Debian DSA