Impact
Chrome’s ANGLE component contains an out‑of‑bounds read that a crafted HTML page can trigger, allowing memory that may contain cross‑origin data to be read. The vulnerability exploits a flaw in memory bounds handling, as categorized by CWE‑125, and can lead to confidential information disclosure without affecting integrity or availability directly.
Affected Systems
The flaw exists in Google Chrome running on Windows, affecting any version prior to 150.0.7871.46. Users of older browsers are susceptible when visiting malicious web pages that leverage ANGLE rendering.
Risk and Exploitability
The EPSS score of < 1 % indicates a low exploitation probability, reflecting the rarity of observed attacks. The vulnerability is not listed in CISA KEV. Chromium security severity is medium with a CVSS score of 6.5. Attackers could exploit the flaw by luring users to a crafted HTML page that uses ANGLE rendering, without needing extra privileges or authentication. Although the CVSS score denotes a moderate impact, the low EPSS and absence from KEV suggest that widespread exploitation is unlikely, but the attack remains feasible if an attacker can deliver the malicious page.
OpenCVE Enrichment
Debian DLA
Debian DSA