Impact
An integer overflow in the GPU component of Google Chrome, triggered by a compromised renderer process, permits a remote attacker to extract cross‑origin data from a crafted HTML page. The flaw acts at the GPU driver level and can expose sensitive information from other web sites visited in the same browser session. The associated weakness is integer overflow (CWE–190).
Affected Systems
Google Chrome desktop releases prior to version 151.0.7922.109 on Windows, macOS, and Linux are vulnerable. Users on the stable channel who have not updated to 151.0.7922.109 or later remain exposed.
Risk and Exploitability
The vulnerability is marked high severity, but EPSS is not available and it is not listed in CISA KEV, indicating no widespread exploitation has been reported. The likely attack vector involves an attacker compromising the renderer process and delivering a malicious HTML page. While it does not provide remote code execution, the resulting data leakage could assist in credential theft or other privacy‑breach attacks.
OpenCVE Enrichment