Impact
The vulnerability is an information exposure in the Paint function of Google Chrome. A remote attacker can craft an HTML page that triggers the Paint API, causing the browser to leak sensitive information that it should not disclose. This flaw aligns with CWE‑200 and provides a medium‑severity risk to confidentiality.
Affected Systems
All users running Google Chrome for desktop before update 153.0.8010.52 are affected. The issue was present in any Chrome release older than that specific version. Installing the Chrome update fixes the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate impact, while the EPSS score of less than 1% suggests that exploitation will be rare. The vulnerability is not listed in CISA’s KEV catalog. A remote attacker would need to persuade a user to load a malicious HTML page, which can occur via phishing or malicious web content. Once the page is rendered, the crafted interaction triggers the Paint API, leaking data without user intervention.
OpenCVE Enrichment
Debian DLA
Debian DSA