Impact
An out of bounds read flaw exists in the WebCodecs component of Google Chrome, allowing a remote attacker to read memory beyond the bounds of an allocated buffer. The resulting memory leak can expose sensitive data stored in the browser process. The weakness matches CWE-125.
Affected Systems
Google Chrome installations with versions older than 146.0.7680.178 on Windows, macOS, and Linux are susceptible to the issue. The vulnerability applies to all desktop platforms where Chrome is deployed.
Risk and Exploitability
The base CVSS score of 8.1 marks the vulnerability as high severity, although the EPSS score of less than 1% suggests a low probability of exploitation in the near term. It is not listed in CISA’s KEV catalog. Based on the description, the attack vector is a remote web page that a user might visit, allowing the attacker to trigger the out of bounds read without additional user interaction.
OpenCVE Enrichment
Debian DSA