Impact
An out‑of‑bounds read exists in the Chromecast component of Google Chrome. A compromised renderer process can read memory beyond intended buffers, potentially leaking sensitive data to an attacker through a crafted web page. The flaw is a classic input validation weakness (CWE‑20). It allows an attacker to obtain confidential information, but only if the attacker first gains the privilege to inject data into the renderer process; it does not grant code execution or unrestricted system access.
Affected Systems
The vulnerability affects Google Chrome browsers prior to version 149.0.7827.53 on all platforms that include the Chromecast feature. It does not impact older browsers that omit Chromecast or running chromeless instances without that module.
Risk and Exploitability
No public CVSS score is available, and the EPSS score is missing, so we lack quantitative exploitation likelihood data. The flaw is not listed in the CISA KEV catalog. The attack vector requires a compromised renderer process and a crafted HTML/Chromecast payload, making exploitation more complex. However, because the renderer typically runs with elevated privileges, a successful read could lead to significant data exposure if combined with other foothold conditions.
OpenCVE Enrichment