Impact
An integer overflow (CWE-190) in the ANGLE graphics library in Google Chrome for macOS allows a remote attacker to craft a malicious HTML page that triggers the overflow. The overflow can leak contents of process memory, potentially exposing sensitive information. This flaw is also associated with CWE-472 and poses a confidentiality breach.
Affected Systems
Google Chrome on macOS, versions earlier than 149.0.7827.53.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score is < 1%, suggesting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it by hosting or delivering a specially crafted web page that the victim visits, making the attack vector likely remote and browser‑mediated.
OpenCVE Enrichment
Debian DSA