Impact
An out-of-bounds read bug exists in ANGLE, the graphics library used by Chrome, that allows a remote attacker who has already compromised the renderer process to read memory contents beyond the intended bounds. This missing memory read can expose potentially sensitive data stored in process memory and is classified as a medium severity vulnerability. The weakness originates from improper bounds checking during memory accesses.
Affected Systems
Google Chrome users running any version prior to 149.0.7827.53 are susceptible. The patch that mitigates the flaw is released in Chrome 149.0.7827.53 and later.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA KEV. A successful exploitation requires the attacker to have already compromised the renderer process, implying that sandbox containment must be breached. Because the attacker already possesses elevated privileges within the renderer, the primary risk is information disclosure rather than remote code execution. The medium severity rating and lack of publicly available exploit data suggest a moderate but non‑zero threat level to affected installations.
OpenCVE Enrichment