Impact
An observed discrepancy in CSS prior to 153.0.8010.47 allows a remote attacker to craft a malicious HTML page that leaks sensitive information. The vulnerability is described as a CWE‑203 and CWE‑204 issue, which refers to information disclosure through inconsistent data handling. The description does not specify the exact type of data that can be exposed, but it is inferred that the attacker can read values that should be hidden by CSS rules, potentially leading to confidentiality loss.
Affected Systems
Google Chrome browsers running any version before 153.0.8010.47, across all supported operating systems, are affected by this rendering bug.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, while the EPSS score of less than 1%. The likely attack vector is remote, whereby an attacker serves a crafted HTML page to a victim’s browser. The vulnerability is not listed in CISA’s KEV catalog, implying no widespread exploitation is currently documented.
OpenCVE Enrichment
Debian DLA
Debian DSA