Impact
The vulnerability is an integer overflow in Chrome’s Chromoting component on Windows, allowing a local attacker to read arbitrary data from process memory through a crafted ETW event. This weakness could reveal sensitive information such as authentication tokens or user session data. The flaw is classified as CWE‑472, an integer overflow that compromises confidentiality.
Affected Systems
Google Chrome for Windows versions earlier than 149.0.7827.53 are affected. The issue resides in the Chromoting module bundled with the stable channel on Windows. No other vendors or products are listed.
Risk and Exploitability
The CVSS score is not provided, and EPSS data is unavailable; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local attacker able to execute code within Chrome to craft an ETW event. Exploitation requires local access, but the attacker can read sensitive memory, leading to confidentiality impact. As no active exploit is publicly documented, the exploitation probability is considered low, though local privilege escalation or data leakage remains a possibility.
OpenCVE Enrichment