Impact
This vulnerability is an integer overflow in the Fonts component of Google Chrome, which allows a remote attacker to read information from process memory when a crafted HTML page is loaded. The leaked data can be potentially sensitive, and the flaw is classified as a memory disclosure flaw supporting both integer overflow (CWE-190) and out‑of‑bounds read (CWE-125).
Affected Systems
All users of Google Chrome versions prior to 149.0.7827.53 are affected. The bug exists in the Chrome browser distributed by Google under the Chrome stable channel.
Risk and Exploitability
The exploit requires a remote attacker to serve a malicious HTML page that takes advantage of the overflow. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and the CVSS score is 6.5, which is considered moderate. The possibility of remote memory access poses a risk in environments where the browser is exposed to untrusted content. No public exploit has been reported, but the disclosed information can be sensitive.
OpenCVE Enrichment
Debian DSA