Impact
A heap buffer overflow occurs in the WebML component of Google Chrome when parsing a specially crafted HTML page. The flaw permits an attacker to perform an out‑of‑bounds memory read from the browser’s process. This can expose data stored in memory and compromise the confidentiality of information handled by the browser. The vulnerability is classified as a heap‑based buffer overflow (CWE‑122).
Affected Systems
The issue affects Google Chrome versions prior to 146.0.7680.71 across all supported operating systems, including Windows, macOS, and Linux. Any user who visits a malicious HTML page while running these affected Chrome versions is at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies it as high severity. EPSS indicates a very low exploit probability (<1%), and it is not listed in the CISA KEV catalog. The attack requires a malicious webpage that the user visits; therefore, the vector is remote through the web. The potential impact on confidentiality is significant.
OpenCVE Enrichment
Debian DSA