Impact
A flaw in the ANGLE graphics subsystem of Google Chrome enables a remote attacker to craft an HTML document that triggers an out‑of‑bounds memory read. The weakness, classified as CWE‑125, allows the attacker to read data that resides adjacent to the intended buffer. While the vulnerability does not provide code execution, it permits the exposure of sensitive information from the victim’s memory.
Affected Systems
Google Chrome desktop releases up to version 149.0.7827.52 are affected. The description does not specify operating‑system support, but it is inferred that the vulnerability applies to Chrome on Windows, macOS, and Linux because Chrome is a cross‑platform browser.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑risk vulnerability; the EPSS score remains below 1 % and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to load a specially crafted HTML page, indicating a user‑interaction prerequisite. The flaw permits information disclosure but does not allow the attacker to modify or execute code. Nonetheless, the potential for leaking confidential data warrants prompt mitigation.
OpenCVE Enrichment
Debian DSA