Impact
This vulnerability is an integer overflow in the Fonts component of Google Chrome, which allows a remote attacker to read information from process memory when a crafted HTML page is loaded. The leaked data can be potentially sensitive, and the flaw is classified as a memory disclosure flaw.
Affected Systems
All users of Google Chrome versions prior to 149.0.7827.53 are affected. The bug exists in the Chrome browser distributed by Google under the Chrome stable channel.
Risk and Exploitability
The exploit requires a remote attacker to serve a malicious HTML page that takes advantage of the overflow. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the possibility of remote memory access poses a risk in environments where the browser is exposed to untrusted content. No public exploit has been reported, but the low Chromium security severity does not negate potential impact on systems handling sensitive data.
OpenCVE Enrichment