Impact
A flaw in Chrome’s WebAudio implementation allows a remote attacker to cause an out‑of‑bounds memory read by serving a specially crafted HTML page. The read can expose internal data, potentially compromising confidentiality. The weakness maps to CWE‑125 and is rated high severity by Chromium’s security team.
Affected Systems
The vulnerability affects all Chrome releases prior to version 146.0.7680.165 across Windows, macOS, and Linux platforms. Users of earlier versions should verify their current Chrome version and update accordingly.
Risk and Exploitability
The CVSS score of 8.8 signals high impact, and the EPSS score of less than 1% suggests limited observed exploitation. It is not listed in the CISA KEV catalog. Based on the description, the attack vector is a maliciously crafted web page that the user must load, making the threat easily exploitable in everyday browsing scenarios.
OpenCVE Enrichment
Debian DSA