Impact
An out‑of‑bounds read occurs in the ANGLE graphics layer of Google Chrome, permitting a remote attacker to read memory from the browser process when a carefully crafted HTML page is rendered. The data that may be exposed is potentially sensitive information stored in process memory. The flaw is identified as CWE‑125 and was considered high severity by Chromium security.
Affected Systems
All users running a Google Chrome build prior to version 150.0.7871.46 on any supported operating system are affected, because ANGLE is employed across desktop Chrome builds.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests that exploitation is currently unlikely according to public threat feeds. The vulnerability is not listed in CISA’s KEV catalog. Attackers must deliver a malicious HTML page that a user chooses to visit; the attack relies entirely on the browser’s rendering engine to trigger the out‑of‑bounds read.
OpenCVE Enrichment
Debian DLA
Debian DSA