Impact
An improper GPU implementation in Google Chrome for Mac before version 149.0.7827.53 enables a remote attacker to leak information across origins through a crafted HTML page. The flaw leads to an information exposure weakness (CWE‑200) and a policy bypass weakness (CWE‑346), allowing data that should remain private to be accessed by an external entity. This highlights a confidentiality compromise rather than a remote code‑execution vector.
Affected Systems
The vulnerability affects Google Chrome on macOS browsers built before the 149.0.7827.53 release. Users running older Chrome versions on Mac may be exposed to the data leakage risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS score of <1% and lack of KEV listing suggest limited exploitation likelihood. The likely attack vector, inferred from the description, is a malicious web page that a user visits, which drives the GPU subsystem to reveal cross‑origin data. While no active exploits are reported, the situation warrants updating the browser promptly to mitigate the exposure.
OpenCVE Enrichment
Debian DSA