Impact
An out‑of‑bounds read occurs within Chrome’s video processing code on ChromeOS. When a renderer process is already compromised, a specially crafted HTML page can trigger the read, allowing the attacker to access potentially sensitive data stored in the renderer’s memory. This is an information‑disclosure vulnerability with a high severity rating from Chromium’s security team.
Affected Systems
The flaw impacts Google Chrome running on ChromeOS prior to version 149.0.7827.115. All installations of that browser version are susceptible when they host untrusted web content that causes the renderer to execute the vulnerable video routine.
Risk and Exploitability
Attackers must already have attacker control of the renderer process to exploit this weakness. The vulnerability’s severity is high, but no EPSS score is available and it is not listed in CISA’s KEV catalog. Even without a published exploit, the potential to read arbitrary memory makes it a serious risk for exposed systems.
OpenCVE Enrichment