Impact
An out‑of‑bounds read in the WebGL engine allows a remote attacker to read memory contents outside the sandbox by loading a specially crafted HTML page. The flaw is a classic out‑of‑bounds read, identified as CWE‑125, and could expose sensitive data stored in the browser’s memory. The Chromium project rates the severity of this issue as high.
Affected Systems
Google Chrome desktop browsers on the stable channel before version 154.0.8037.92 are affected.
Risk and Exploitability
The CVSS score is 4.7, indicating a moderate overall severity. No EPSS data is currently available and the vulnerability has not been listed in the CISA KEV catalog. Exploitation requires a user to visit a malicious or compromised web page that serves the crafted content, so the attack vector is remote but user‑initiated.
OpenCVE Enrichment