Impact
The flaw is an out‑of‑bounds read in Chrome’s ANGLE graphics component on macOS. A remote attacker who has already compromised the renderer process can craft a malicious HTML page to trigger the read, exposing sensitive information stored in the browser’s process memory. The vulnerability does not allow arbitrary code execution, but it can lead to disclosure of confidential data within the renderer’s memory space.
Affected Systems
Google Chrome on macOS versions earlier than 150.0.7871.47 is affected. In environments where these browsers run, the vulnerability is exploitable if a renderer process is compromised.
Risk and Exploitability
With a CVSS score of 5.3, this issue is considered medium severity by Chromium and is not listed in CISA’s KEV catalog. No EPSS score is available, indicating a lack of publicly reported exploitation data. The flaw requires that the attacker already have compromised the renderer process; exploitation therefore is limited to browsers that have been compromised or that run untrusted content. If exploited, only the confidentiality of data accessible to the renderer is affected, and no arbitrary code execution or broader system impact is possible.
OpenCVE Enrichment
Debian DLA
Debian DSA