Impact
The vulnerability is an out-of-bounds read and write in the Tint component of Google Chrome on macOS. A crafted HTML page can trigger the flaw, enabling a remote attacker to read or write beyond allocated memory, which could lead to arbitrary code execution. The flaw is classified as a high severity issue.
Affected Systems
The affected product is Google Chrome on macOS, specifically any version prior to 145.0.7632.116. The documentation does not indicate that other operating systems such as Linux or Windows are impacted.
Risk and Exploitability
The CVSS score of 8.8 reflects a high risk level, yet the EPSS score of less than 1% suggests a low probability of exploitation by the broader community. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Attackers would most likely exploit the flaw by delivering a malicious web page that leverages the out-of-bounds memory access to compromise system resources.
OpenCVE Enrichment
Debian DSA