Impact
An out‑of‑bounds read was discovered in GWP‑ASan used by Google Chrome, allowing a local attacker to read arbitrary areas of the browser’s process memory. The vulnerability is classified as CWE‑125 and is rated medium severity by Chromium’s internal assessment. The read can potentially leak sensitive information that a user has accessed while browsing.
Affected Systems
Affected systems are desktop installations of Google Chrome from vendors such as Google. The flaw exists in all release builds prior to Chrome version 149.0.7827.53; the security advisory linked above includes the stable channel update that removes the issue.
Risk and Exploitability
Risk and exploitability are moderate. The vulnerability requires a local attacker to execute a crafted file that Chrome processes, so remote exploitation is not possible. The CVSS score of 6.5 indicates medium severity, the EPSS score of <1% demonstrates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, highlighting limited overall threat likelihood given the local‑only attack vector.
OpenCVE Enrichment
Debian DSA