Impact
The vulnerability is a use‑after‑free flaw in WebGL that can be triggered by a crafted HTML page. If successfully exploited, an attacker may read data from Chrome’s process memory, potentially exposing sensitive information. The weakness is identified as CWE‑416 and CWE‑825 and is classified as a medium severity issue by the Chromium team.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. Users running any older Chrome stable release may be vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The damage of the flaw is limited to information disclosure; there is no evidence of code execution or denial‑of‑service impact. The attack can be carried out remotely by a malicious web page, which is the likely vector inferred from the description. The EPSS score is < 1%, suggesting a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA