Impact
An out‑of‑bounds read was discovered in the Dawn graphics engine of Google Chrome before version 151.0.7922.72. The flaw, identified as a buffer over‑read (CWE‑125), allows a remote attacker, via a crafted HTML page, to read arbitrary memory contents and potentially expose confidential data.
Affected Systems
The vulnerability is present in Google Chrome running on the desktop stable channel, affecting all versions older than 151.0.7922.72 across supported operating systems.
Risk and Exploitability
With a CVSS score of 8.1 the flaw is considered high severity, but the EPSS score of less than 1 % indicates a very low current exploitation probability. The attack requires an attacker to host a malicious web page that the victim opens, so phishing or drive‑by download vectors are typical. The vulnerability is not listed in the CISA KEV catalog, reducing awareness of active exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA