Impact
A flaw in the Blink rendering engine of Google Chrome releases prior to 146.0.7680.153 allows an attacker to read memory locations beyond the bounds of allocated buffers when a specially constructed HTML page is rendered. This out‑of‑bounds memory read could expose sensitive data stored in the browser process, corresponding to CWE‑125. The vulnerability is classified as high severity by the Chromium security team.
Affected Systems
Google Chrome browsers on Windows, macOS, and Linux are affected. The issue exists in all Chrome builds dated before 146.0.7680.153, regardless of the operating system.
Risk and Exploitability
The CVSS v3.1 score is 8.8, indicating a high impact if exploited. The EPSS score of less than 1% suggests that attacks using this flaw are currently infrequent, yet the vulnerability is not listed in the CISA KEV catalog. An attacker could exploit it by hosting a malicious web page that the victim opens, triggering the out‑of‑bounds read.
OpenCVE Enrichment
Debian DSA