Impact
An out-of-bounds read in the Codecs component of Google Chrome allows a remote attacker to read sensitive information from process memory through a specially crafted HTML page. The issue, identified as CWE-125, can expose data that should remain confidential, presenting a medium severity risk to user information privacy.
Affected Systems
Chrome versions prior to 150.0.7871.47 on all supported operating systems are affected. Any installation of the vulnerable browser can be compromised if the user loads a malicious web page containing the exploit code.
Risk and Exploitability
With a CVSS score of 6.5, this vulnerability is moderately severe. No EPSS data is currently available, and it is not listed in the CISA KEV catalog. Exploitation requires only remote access; an attacker must deliver a crafted page that the victim opens, and no special privileges are needed beyond normal browsing. The vulnerability is fully remote and does not rely on local execution or extra user interaction beyond visiting the malicious site.
OpenCVE Enrichment
Debian DLA
Debian DSA