Impact
The vulnerability is an out‑of‑bounds read in the WebRTC component of Google Chrome. The bug exists only when an attacker has already compromised the GPU process, after which a specially crafted HTML page can trigger heap corruption. This weakness is classified as CWE‑125.
Affected Systems
Users running Google Chrome on desktop operating systems with any version earlier than 149.0.7827.103 are affected. The flaw resides in the WebRTC implementation that interacts with the GPU process. Upgrading to Chrome 149.0.7827.103 or later includes the patch.
Risk and Exploitability
Chromium lists the severity as High, and the CVSS score is 7.5. The EPSS score is unavailable and the vulnerability is not in the CISA KEV catalog. Exploitation requires dual conditions: prior compromise of the GPU process and the delivery of a crafted HTML document. In environments where the GPU process can be compromised or is exposed to untrusted content, the risk is moderate to high. Updating to a fixed release mitigates the threat.
OpenCVE Enrichment