Impact
Google Chrome prior to 147.0.7727.55 contains a heap buffer overflow in the WebML component, classified as CWE‑122. A crafted HTML page can trigger the overflow, allowing a remote attacker to read process memory and potentially exfiltrate sensitive data. The vulnerability does not grant arbitrary code execution, but it does break confidentiality by leaking memory contents that may include credentials, secrets, or other confidential information.
Affected Systems
All desktop installations of Google Chrome running a version earlier than 147.0.7727.55 are vulnerable. The issue affects the Chrome browser shipped for Windows, macOS, and Linux platforms.
Risk and Exploitability
Chromium rates the issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a maliciously crafted web page that the user opens, implying that exploitation requires user interaction with a malicious site but can occur without special privileges.
OpenCVE Enrichment
Debian DSA