Impact
The vulnerability is an out‑of‑bounds read in the CSS engine of Google Chrome. An attacker can serve a specially crafted HTML page that triggers the engine to read memory beyond the intended buffer. Because the read exposes sensitive data in memory, the flaw is rated high severity. The exposed information could range from user data to system secrets, potentially enabling further exploitation such as code execution if an attacker can also influence memory writes or combine the read with other weaknesses.
Affected Systems
The affected product is Google Chrome across all supported operating systems – Windows, macOS, and Linux – until version 146.0.7680.165. Any installation of Chrome that remains at a version earlier than the specified update is vulnerable. Users on the stable channel are most likely impacted; those on beta or dev channels may have already received fixes.
Risk and Exploitability
The CVSS score of 8.8 indicates a serious threat, while the EPSS score of less than 1% suggests that exploitation is not currently common. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attacks rely on a remote web page, so a network‑connected machine that opens or renders a malicious URL can be compromised. No minimum privilege is required, but the attacker must be able to load arbitrary HTML into Chrome, for example by visiting a phishing site or compromising a site that users visit.
OpenCVE Enrichment
Debian DSA