Impact
An integer overflow in the ANGLE graphics subsystem of Google Chrome allows a remote attacker to cause Chrome to read memory beyond the intended bounds when rendering a specially crafted HTML page. The overflow can result in arbitrary memory disclosure, potentially exposing sensitive data loaded in the browser process. The weakness is a classic integer overflow, mapped to CWE‑472, and the Chromium security team rates the severity of the issue as medium.
Affected Systems
Google Chrome on Windows prior to version 147.0.7727.138 is affected. The vulnerability is present in all Windows builds of Chrome that have not applied the update component that fixes the ANGLE overflow. Only systems running Windows and Chrome before the stated version need remediation.
Risk and Exploitability
The attack vector is remote and requires the victim to load a maliciously crafted web page. The exploit is client‑side and does not require network privileges beyond normal browser access. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The CVSS score of medium indicates that while the vulnerability does not provide direct remote code execution, it can lead to information disclosure. Once the crafted page is rendered in a user’s Chrome session, the attacker could read arbitrary memory content, potentially leaking confidential data.
OpenCVE Enrichment