Impact
The ANGLE rendering component of Google Chrome contains a flaw that allows an out‑of‑bounds memory read or write to be triggered by a specially crafted HTML page. A remote attacker could read or write data beyond the intended bounds, leading to memory corruption in the browser process and compromising the integrity of user data. This vulnerability is classified under CWE‑125.
Affected Systems
All users running Google Chrome versions earlier than 149.0.7827.53, regardless of operating system, are affected because the flaw exists in the stable channel's ANGLE engine.
Risk and Exploitability
The flaw has a CVSS score of 8.8, reflecting high severity, but an EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. It is not listed in the CISA KEV catalog. A likely attack vector is a malicious web page rendered by the browser; no additional privileged or network conditions are required. Consequently, while the potential impact is severe, the likelihood remains modest until further monitoring or evidence of exploitation emerges.
OpenCVE Enrichment
Debian DSA