Impact
An observable discrepancy in the Document Object Model implementation in Google Chrome before version 153.0.8010.36 allows a remote attacker to obtain sensitive information by loading a specially crafted HTML page. The flaw is a client‑side information disclosure weakness (CWE‑203). When the browser processes the malicious page, the inconsistent DOM state exposes data that should not be accessible to the page, such as form entries or session identifiers.
Affected Systems
Google Chrome browsers with a version earlier than 153.0.8010.36 are affected. The issue applies to all builds of Chrome that have not applied the latest stable update.
Risk and Exploitability
The advisory lists the vulnerability as Medium severity with a CVSS score of 6.5. EPSS score is less than 1% and the vulnerability is not included in the CISA KEV catalog, indicating no widespread exploitation has been observed yet. The likely attack vector is remote; an attacker would need to persuade a user to visit a malicious web page (social engineering). Successful exploitation results in the theft of sensitive user data but does not provide remote code execution or elevated privileges. The risk level remains moderate for typical users.
OpenCVE Enrichment
Debian DLA
Debian DSA