Impact
The vulnerability is an out‑of‑bounds read in WebRTC on Google Chrome versions prior to 149.0.7827.53. A malicious web page can trigger the bug and allow a remote attacker to read arbitrary data from the browser’s process memory. The consequence is potentially sensitive information disclosure, identified as CWE-125.
Affected Systems
The affected product is Google Chrome built on the Chromium engine. Any desktop installation of Chrome before version 149.0.7827.53 is vulnerable, unless the user has already applied the update released in the June 2026 stable channel.
Risk and Exploitability
The advisory lists a CVSS score of 6.5 and an EPSS score of less than 1%, indicating a moderate likelihood of exploitation. The vulnerability is not listed in the KEV catalog, and the attack vector is remote through a crafted HTML page that triggers the out‑of‑bounds read. Until the patch is applied, an attacker who can host a malicious page accessed by the victim can leak process memory contents.
OpenCVE Enrichment
Debian DSA