Impact
This CVE identifies an out-of-bounds read in the ANGLE graphics layer of Google Chrome. The flaw can be triggered by rendering a specially crafted HTML page, allowing a remote attacker to read arbitrary data from the browser’s process memory. The memory leakage may expose credentials or user‑entered data, constituting a loss of confidentiality.
Affected Systems
Google Chrome is the affected product. Versions earlier than 150.0.7871.46 are vulnerable; updating to 150.0.7871.46 or later removes the flaw. No other vendors or products are listed as affected.
Risk and Exploitability
Exploitation requires the victim to be tricked into loading a malicious web page, such as through phishing or a malicious advertisement. Based on the description, it is inferred that the attacker must rely on a user who visits or clicks on a specially crafted HTML page. The CVSS score of 6.5 indicates medium severity, while an EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not currently listed in CISA KEV, meaning no documented exploits exist yet, but the memory disclosure remains a concern if an attacker succeeds.
OpenCVE Enrichment
Debian DLA
Debian DSA