Impact
An observable discrepancy in font rendering occurs in Google Chrome versions before 153.0.8010.47. The flaw permits a remote attacker to supply a specially crafted HTML page that, when viewed by a user, can leak sensitive information. The weakness is an information‑leak scenario, classified as CWE-203 and CWE-204. The result is the accidental disclosure of data that should remain private to the victim’s system or browsing session.
Affected Systems
Google Chrome browsers with versions earlier than 153.0.8010.47 are affected. Users of the stable channel on desktop platforms are at risk until they upgrade the browser.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires the user to open a maliciously crafted HTML page, typically through social engineering, enabling the attacker to read data that can be inferred from font rendering differences.
OpenCVE Enrichment
Debian DLA
Debian DSA