Impact
An out‑of‑bounds read in the ANGLE graphics subsystem of Google Chrome allowed a remote attacker to read memory beyond intended bounds, exposing cross‑origin data. The flaw does not provide code execution but can reveal sensitive information stored in Chrome’s process memory, which corresponds to a high severity rating in Chromium’s security severity assessment. The vulnerability is identified as a memory read error (CWE‑125).
Affected Systems
Versions of Google Chrome older than 150.0.7871.46 are affected. The vulnerability involves the ANGLE component, which is part of Chrome’s graphics stack (inferred from the description). All users running those versions are potentially exposed if they visit malicious web content.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium severity range, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. According to the description, a remote attacker can exploit the flaw by hosting a crafted HTML page and reading memory beyond intended bounds, resulting in leakage of cross‑origin data.
OpenCVE Enrichment
Debian DLA
Debian DSA