Impact
This CVE describes an out‑of‑bounds read in the ANGLE graphics component of Google Chrome that can be triggered by rendering a crafted HTML page. The over‑read allows a remote attacker to access arbitrary data from the browser’s process memory, potentially exposing sensitive information such as authentication tokens or user‑entered text. The weakness is a classic buffer over‑read (CWE‑125), and its primary impact is loss of confidentiality.
Affected Systems
The affected vendor is Google, product Chrome. Versions prior to 150.0.7871.46 are vulnerable; upgrading to 150.0.7871.46 or later mitigates the issue. No other vendors or products are listed as affected.
Risk and Exploitability
Exploitability requires the victim to load a malicious HTML page, so some user interaction or a delivery vector such as phishing or malicious advert is needed. The CVSS score of 6.5 indicates medium severity, while an EPSS score of <1% shows a very low probability that attackers will target this flaw. The absence from CISA KEV suggests no documented exploitation yet, but the vulnerability could be used to exfiltrate memory contents if the attack succeeds.
OpenCVE Enrichment
Debian DLA
Debian DSA