Impact
Based on the description, an out-of-bounds read vulnerability exists in Chrome’s SurfaceCapture component in all releases before 150.0.7871.47. A malicious web page can be crafted to cause Chrome to read memory. This defect is classified as CWE‑125 and is listed by Chromium as a medium severity issue.
Affected Systems
Based on the description, it is inferred that all versions of Google Chrome older than 150.0.7871.47 are affected. The referenced stable‑channel update page indicates that the new version 150.0.7871.47 is the first to contain the fix, so it is inferred that all stable‑channel releases prior to that point are vulnerable. It is inferred that all supported operating systems running Chrome below the patched version are susceptible to this issue.
Risk and Exploitability
Based on the details, the CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The flaw resides in Chrome’s SurfaceCapture component and can be triggered by a malicious web page that forces the browser to perform an out‑of‑bounds memory read; this allows a remote attacker to acquire sensitive information from memory. The vulnerability is not yet listed in the CISA KEV catalog, but the attack path is an in‑browser exploitation that only requires the user to visit a crafted site.
OpenCVE Enrichment
Debian DLA
Debian DSA