Impact
An out‑of‑bounds read vulnerability in Chrome’s input handling on Linux allows a remote attacker to read data from the browser’s process memory via a specially crafted HTML page. The flaw can cause the leakage of potentially sensitive information, compromising confidentiality of the user’s private information stored in Chrome’s memory space. The weakness is identified as CWE‑125: Out‑of‑Bounds Read.
Affected Systems
The vulnerability affects Google Chrome running on Linux versions earlier than 149.0.7827.53. The affected product is the stable channel desktop distribution of Chrome on Linux desktop environments. Users of older Chrome releases who have not installed the recent firmware update are at risk.
Risk and Exploitability
The CVSS score of 6.5 is classified as Medium. The EPSS score indicates a very low exploitation probability (less than 1%) and the flaw is not listed in CISA’s KEV catalog. The attack vector is remote: a malicious web page can trigger the read by a user who opens the page in Chrome. Because user interaction is required and the bug only leaks data from the browser’s own memory, the overall likelihood of exploitation remains moderate. However, any successful exploitation results in accidental disclosure of sensitive data in the process memory and should be mitigated as soon as possible.
OpenCVE Enrichment
Debian DSA