Impact
An integer overflow in Chrome’s ANGLE component on Windows allows a remote attacker who has already compromised the renderer process to read that process’s memory, potentially exposing sensitive data. The flaw follows the typical pattern of integer overflows, classified as CWE‑472, and is rated medium severity in Chromium. It does not provide arbitrary code execution, but it can expose privileged information contained in the renderer’s memory.
Affected Systems
All Windows installations of Google Chrome using a browser version earlier than 150.0.7871.46 are affected. The vulnerability is limited to the renderer process; only renderers that have been previously compromised can exploit the flaw.
Risk and Exploitability
Exploitation requires a prior compromise of the renderer. The most likely attack vector is a browser exploitation chain or social engineering that lures the user to a malicious site that triggers the overflow. The CVSS score of 5.3 signals moderate impact, the EPSS score of less than 1 % indicates a low probability of widespread attacks, and the vulnerability is not listed in CISA KEV. Because it can leak privileged data without providing code execution, the risk is moderate but significant for users handling confidential information while browsing.
OpenCVE Enrichment
Debian DLA
Debian DSA