Impact
The vulnerability is an integer overflow in the ANGLE graphics abstraction layer used by Google Chrome. A crafted HTML page can trigger the flaw and allow a remote attacker to read potentially sensitive data from Chrome’s process memory. The issue is identified as CWE-190 and CWE-472 and is rated as Medium severity by Chromium security teams.
Affected Systems
Google Chrome versions prior to 148.0.7778.216, including all stable channel releases before that version, are vulnerable to the flaw. Users running earlier stable builds are at risk until they update to a patched release.
Risk and Exploitability
Exploit details are not publicly disclosed, and the EPSS score is not available, but the vulnerability is not listed in CISA KEV. The CVSS score is 6.5, indicating medium severity. Although a remote attacker would need to load a malicious page in the victim’s browser, the risk is moderate because the flaw only permits memory disclosure rather than full code execution. Until Chrome receives an advisory indicating active exploitation, the primary risk remains exposure of private data through crafted web content.
OpenCVE Enrichment