Impact
An out-of-bounds read flaw in the Layout component of Google Chrome before version 150.0.7871.47 allows a remote attacker to craft an HTML page that can read arbitrary data from the browser process memory. The vulnerability is a memory safety issue (CWE‑125) that can expose sensitive information stored in memory, such as user data or session information, by accessing data beyond the bounds of allocated buffers.
Affected Systems
All desktop installations of Google Chrome built on the Chromium engine whose version is older than 150.0.7871.47 are affected. No specific operating systems or builds were excluded in the advisory.
Risk and Exploitability
The CVSS score of 6.5 reflects medium severity. The EPSS score of < 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a crafted HTML page via a malicious website or phishing email, which a victim would load in the browser. No public exploits have been reported, and the issue is considered to be purely informational if it is successfully triggered.
OpenCVE Enrichment
Debian DLA
Debian DSA