Impact
A component of Chrome known as ANGLE contains an out‑of‑bounds read that lets a remote attacker read sensitive information from the browser’s process memory when a crafted HTML page is viewed. This flaw is a classic out‑of‑bounds read (CWE‑125), resulting directly in information disclosure without code execution or privilege escalation.
Affected Systems
Google Chrome running on Linux operating systems and dated earlier than version 149.0.7827.53 are affected. The vulnerability has been fixed in the stable channel release 149.0.7827.53 and later.
Risk and Exploitability
The flaw is rated medium severity by Chromium and has a CVSS score of 6.5, an EPSS score of less than 1%, and is not listed in CISA’s KEV catalog. Attackers can exploit it purely from a remote web page that loads crafted HTML while the browser is running, making the risk largely dependent on user browsing habits rather than privileged or local execution requirements.
OpenCVE Enrichment
Debian DSA