Impact
This vulnerability results from insufficient validation of untrusted input in Chrome’s GPU process. An attacker who has already compromised the renderer process can craft a malicious HTML page that exploits the flaw, allowing the attacker to read data from other origins and leak confidential information. The weaknesses are classic input validation issues (CWE‑20 and CWE‑346).
Affected Systems
Affected vendors and products include Google Chrome; versions prior to 149.0.7827.53 are vulnerable. This includes all Chrome stable channel releases that are earlier than the patched 149.0.7827.53 build.
Risk and Exploitability
The CVSS score is 5.3, indicating medium severity, and the EPSS score is <1%, with the vulnerability not listed in the CISA KEV catalog. The attack requires the attacker to have already compromised the renderer process, so the exploitation likelihood depends on success of other prior compromises. Based on the Medium severity rating in Chromium and the lack of publicly known exploitation, the overall risk is moderate, but the potential for confidential data leakage warrants urgent attention.
OpenCVE Enrichment
Debian DSA