Impact
A heap buffer overflow occurs in the WebML component of Google Chrome when processing a crafted HTML page. The overflow allows a remote attacker to read data from the browser’s process memory beyond the intended buffer, potentially exposing credentials, personal data, or other confidential information. The vulnerability is classified under buffer‑copy‑without‑checking‑size and buffer‑overflow weaknesses (CWE-120, CWE-122).
Affected Systems
The flaw affects all versions of Google Chrome prior to build 147.0.7727.55 on macOS, Linux, and Windows operating systems.
Risk and Exploitability
The CVSS base score of 4.3 indicates low‑to‑moderate severity, while an EPSS score below 1% suggests exploitation is unlikely in the wild. The vulnerability requires a crafted HTML page that the user must view, meaning social engineering or compromised sites are needed for exploitation. It is not listed in CISA’s Known Exploited Vulnerabilities catalog, further reducing its immediate threat level. The likely attack vector is a remote malicious web page.
OpenCVE Enrichment
Debian DSA