Impact
Out of bounds read in the Dawn rendering engine of Google Chrome on Windows allows a remote attacker, via a crafted HTML page, to read memory beyond the intended bounds and leak cross‐origin data. The flaw is a classic out‑of‑bounds read identified as CWE‑125 and results in the exposure of data that the browser should isolate, compromising confidentiality.
Affected Systems
Google Chrome for Windows, versions before 149.0.7827.103. The vulnerability was present in all earlier builds of the stable channel released before that version.
Risk and Exploitability
The vulnerability is exploitable only when a user opens a malicious web page in Chrome on Windows, giving a remote attacker the ability to read sensitive data from other origins. Although no EPSS score is available, CISA does not list it in KEV, indicating no known widespread exploitation yet. The CVSS score of 4.3 indicates a moderate overall risk, while the high Chromium security severity suggests significant risk if the flaw is used. Organizations should act promptly to mitigate potential data leakage.
OpenCVE Enrichment