Impact
An out‑of‑bounds read in the ANGLE graphics subsystem of Google Chrome allowed a remote attacker to read memory beyond intended bounds, exposing cross‑origin data. The flaw does not grant code execution but can reveal sensitive information stored in Chrome’s process memory, meeting the criteria for a high security severity rating from Chromium. The vulnerability is identified as a memory read error (CWE‑125).
Affected Systems
Versions of Google Chrome older than 150.0.7871.46 are affected. The vulnerability involves the ANGLE component, which is part of Chrome’s graphics stack (this is inferred from the description). All users running those versions are potentially exposed if they visit malicious web content.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium severity range, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in production. The vulnerability is not listed in CISA’s KEV catalog. According to the description, a remote attacker can exploit the flaw by hosting a crafted HTML page that a victim opens; no remote code execution or privilege escalation is possible, but confidentiality can be impacted through arbitrary data disclosure.
OpenCVE Enrichment
Debian DLA
Debian DSA