Impact
An integer overflow in the WebNN component of Google Chrome, affecting versions prior to 150.0.7871.47, can be triggered by a specially crafted HTML page. The overflow causes the browser to read unintended portions of process memory, exposing potentially sensitive data. The vulnerability is classified as CWE‑457, representing an instance of undefined behaviour that may lead to data leakage without granting execution privileges.
Affected Systems
Google Chrome browsers running any build before version 150.0.7871.47 are vulnerable. This includes all stable channel releases prior to the June 2026 update that introduced the fix. Users of older Chromium‑based browsers and, if they incorporate the same WebNN library, Android WebView components may also be affected; this inference is based on the shared use of the same library and not directly stated in the advisory.
Risk and Exploitability
The flaw operates as a remote information‑disclosure vector, activated by loading a malicious web page. The CVSS score of 6.5 indicates a moderate severity, while no EPSS score is available to estimate exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploits have been observed. Nevertheless, the ability to read arbitrary memory poses a confidentiality risk that could be leveraged by malicious websites or malware, particularly in environments where Chrome runs with elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA