Impact
An out‑of‑bounds read in the Blink rendering engine of Google Chrome allows a remote attacker to read arbitrary memory when a specially crafted HTML page is loaded in the browser. This flaw can expose sensitive data from the browser process, leading to information disclosure. The vulnerability is classified as a low security severity by Chromium but carries a CVSS score of 8.1.
Affected Systems
Google Chrome versions earlier than 147.0.7727.55 are affected. The issue applies to all major operating systems supported by Chrome, including macOS, Windows and Linux distributions, as indicated by the related platform identifiers. Users of the stable channel who have not upgraded to 147.0.7727.55 remain exposed.
Risk and Exploitability
The CVSS base score of 8.1 denotes high risk, while the EPSS probability of exploitation is below 1 %, and the issue is not listed in the CISA KEV catalog. Exploitation requires only that a user visit a malicious webpage, so the attack vector is remote and does not need privileged local access. For organizations that run Chrome on desktops or laptops, the potential impact of data leakage warrants prompt remediation.
OpenCVE Enrichment
Debian DSA