Impact
The flaw is a heap buffer overflow in Chrome’s WebGL implementation that permits a remote attacker to read memory beyond the intended bounds through a specially crafted HTML page. The vulnerability could expose private data or be a stepping stone to more serious attacks such as code execution, depending on the information gleaned from the read. The weakness is classified as CWE‑122 and CWE‑787, consistent with out-of-bounds read and write conditions.
Affected Systems
Google Chrome versions earlier than 146.0.7680.165 on all major desktop operating systems – Windows, macOS, and Linux – are affected. The issue specifically targets the WebGL component of the browser, which is available across these platforms.
Risk and Exploitability
The exploit requires the victim to open a malicious web page, making the attack vector remote and browser‑based. The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1 % suggests exploitation is relatively unlikely. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score warrants attention, and once patched, the risk is effectively mitigated.
OpenCVE Enrichment
Debian DSA