Impact
An integer overflow in Chrome’s compositing engine allows a crafted web page to read memory that contains data from a different origin, violating the same‑origin policy and exposing confidential information to an attacker. This flaw can be exploited from the network without any local privileges and results in confidentiality compromise of content that should remain isolated.
Affected Systems
Google Chrome versions earlier than 154.0.8037.97 are affected. Users running these releases are susceptible to the described data‑leak flaw.
Risk and Exploitability
Chromium labels the issue as high severity; while no EPSS score is available, the vulnerability can be triggered by any web page that an end‑user visits, making exploitation highly feasible. The flaw is not listed in the CISA KEV catalog, but the lack of an exploitation probability metric does not reduce the urgency of applying a fix.
OpenCVE Enrichment