Impact
A heap buffer overflow exists in the WebML component of Google Chrome prior to version 147.0.7727.55. The overflow allows a remote attacker to read sensitive data from the browser’s process memory by serving a specially crafted HTML page. The Chrome security team has rated this issue as High severity, indicating that the flaw could expose confidential information if exploited.
Affected Systems
All users of Google Chrome versions earlier than 147.0.7727.55 on any supported operating system (Windows, macOS, Linux) are affected. The vulnerability resides in the WebML module that processes web content, so any instance of the browser that loads user‑supplied HTML could be compromised.
Risk and Exploitability
The flaw is remotely exploitable by hosting or viewing a malicious web page. While the EPSS score is currently unavailable, the CVSS assessment labels the vulnerability as High, signifying significant potential impact. It has not yet appeared in the CISA KEV catalog, but its absence does not reduce the risk of exploitation. An attacker who successfully triggers the overflow can read arbitrary memory, potentially leaking credentials or other private data stored by the browser.
OpenCVE Enrichment
Debian DSA