Impact
The vulnerability is an out‑of‑bounds read within the Headless renderer component of Google Chrome. When the renderer process is already compromised by a remote attacker, a specially crafted HTML page can trigger an out‑of‑bounds read that may enable the attacker to escape the renderer sandbox. This leads to potential execution of arbitrary code outside the browser process. The weakness is classified as CWE‑125 and is considered a Medium severity issue in Chromium’s internal scoring.
Affected Systems
Affected systems belong to the Google Chrome browser. Versions prior to 148.0.7778.216 are susceptible. Users running the stable channel releases before this build need to upgrade to avoid the risk.
Risk and Exploitability
The CVE carries a high severity rating with a CVSS score of 8.3 and an EPSS score of < 1%. It is not listed in the CISA KEV catalog. Exploitation requires an attacker to first compromise the renderer process, then deliver a crafted HTML payload to trigger the out‑of‑bounds read. Thus, the risk is high but can lead to full system compromise if sandbox boundaries are broken. Prompt patching is advised to reduce the attack surface.
OpenCVE Enrichment