Impact
An inappropriate implementation of ANGLE in Chrome’s graphics layer enables remote attackers to load a specially crafted HTML page that causes the browser to leak data from sites the user normally cannot access. The flaw results in cross‑origin information disclosure, potentially exposing sensitive content such as credentials, cookies, or personal data. The vulnerability corresponds to several common weakness enumerations listed by the vendor.
Affected Systems
All versions of Google Chrome earlier than 146.0.7680.178 are affected, regardless of operating system. Users running Chrome on Windows, macOS, or Linux who have not upgraded to a newer revision remain susceptible. The issue is specifically tied to the ANGLE component used in Chrome’s rendering engine.
Risk and Exploitability
The CVSS score of 7.4 classifies the flaw as high severity, yet the EPSS score of less than 1% indicates that exploitation probability is currently low. The vulnerability is not listed in the KEV catalog. Attackers can exploit it by serving a malicious webpage that forces the victim’s browser to expose cross‑origin data, so the primary mitigation is to apply the patched Chrome version.
OpenCVE Enrichment
Debian DSA